Missing User Warnings
Medium
- Confidence
- 96% confidence
- Finding
- The README explicitly instructs users to run hooks on every agent turn and names a pre-query and post-response flow, which implies automatic transmission of conversation data to an external service. Because there is no accompanying privacy notice, consent guidance, data minimization guidance, or retention/security disclosure, deployers may unknowingly exfiltrate sensitive user prompts and model responses on every interaction.
