Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill explicitly advertises access to a team's 'entire coding history' and project context, but does not present a prominent, concrete privacy warning about what data may be collected, searched, or exposed through the CLI. In a security-sensitive agent context, this can lead users to authorize broad access to historical code, session data, and team knowledge without informed consent or understanding of retention and exposure risks.
