Missing User Warnings
Medium
- Confidence
- 88% confidence
- Finding
- The specification explicitly directs persistent storage of interaction-derived emotional state in a per-agent JSON file under the user's home directory, but it provides no notice, consent model, retention policy, or guidance on protecting that data. Even if the stored data is 'just mood', it is derived from user interactions and can reveal behavioral patterns, relationship inferences, session frequency, and other sensitive metadata over time.
