Missing User Warnings
Medium
- Confidence
- 83% confidence
- Finding
- The README explicitly tells users to place real company data into a local YAML file and then generate decision artifacts under logs/, but it does not warn that these outputs may contain sensitive business information such as pricing strategy, runway, ARR/MRR, constraints, and internal decisions. While this is not an exploit by itself, it creates a real confidentiality risk because users may unintentionally retain, commit, or share sensitive files produced by the skill.
