Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The skill explicitly provides an export function that serializes the full knowledge base, including complete document contents and metadata, which can contain sensitive construction documents, contracts, safety reports, or project identifiers. In a RAG skill focused on enterprise/construction knowledge bases, encouraging unrestricted export without any warning, access control guidance, redaction, or minimization increases the risk of accidental data exfiltration and oversharing.
