Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The skill explicitly states that command output will be logged to a memory file, but the user-facing description does not warn about this data retention behavior. In a shell-execution skill that also retrieves secrets and handles system tasks, command output may contain sensitive data such as tokens, file paths, environment values, or operational details, so undisclosed logging increases privacy and security risk.
