Missing User Warnings
Medium
- Confidence
- 89% confidence
- Finding
- The heartbeat sends detailed runtime telemetry, including process memory usage and uptime, to the configured gateway on every interval without any consent flow, minimization, or indication to the user. In this skill context, the gateway URL is configurable and defaults to plain HTTP, so operational metadata may be exposed to an untrusted or intercepted endpoint and can aid host fingerprinting or surveillance.
