Missing User Warnings
Medium
- Confidence
- 90% confidence
- Finding
- The skill explicitly instructs the agent to run queries against the user's org files and org-roam knowledge base without clarification, including prompts like 'What do you know about Sarah?' and 'Search my notes for Y'. This can cause the agent to access and summarize potentially sensitive personal data without confirming scope, identity, or user intent, increasing the risk of over-broad disclosure from private notes.
