Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The skill reads local memory files and sends their contents to an embedding service via the Ollama CLI or local HTTP API without any explicit notice, consent, or data classification checks. Even if Ollama is expected to run locally, this still discloses potentially sensitive workspace content to another process/service boundary and may surprise users or violate local privacy expectations.
