Missing User Warnings
Medium
- Confidence
- 90% confidence
- Finding
- The script sends full PR titles, branch names, file lists, and diffs to external agent processes for analysis without a strong explicit consent gate or data-classification check. In the context of a repository-governance skill, this can expose proprietary code, credentials accidentally present in diffs, or sensitive metadata to downstream model providers or local integrations.
