Missing User Warnings
Medium
- Confidence
- 83% confidence
- Finding
- The `polish --file=...` workflow encourages reading arbitrary local files containing owner profiles without any warning about sensitive data exposure or scope restriction. In practice, users may point the skill at files holding personal, corporate, or strategic information, and the skill's broad Read/Glob/Grep permissions increase the chance of over-collection or unintended disclosure into model context.
