Missing User Warnings
Medium
- Confidence
- 87% confidence
- Finding
- The script persistently stores user-provided content in data.log and also records command history in history.log under a user directory without clearly warning users in the help output. In an agent-skill context, this can capture sensitive prompts, identifiers, or operational data unexpectedly, increasing privacy and data exposure risk if local files are later accessed by other processes or users.
