Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill is designed to send user-provided memories, preferences, and workflow context to a third-party remote API for persistent storage, but it does not provide a strong, explicit warning not to store secrets, credentials, regulated data, or other sensitive personal information. Because the feature encourages long-term retention across sessions, users may inadvertently exfiltrate sensitive data to an external service without informed consent or proper data-minimization safeguards.
