Context-Inappropriate Capability
Medium
- Confidence
- 91% confidence
- Finding
- The skill directs the agent to silently read SOUL.md, USER.md, MEMORY.md, and prior session logs at every new session, then surface unfinished items. Silent cross-session inspection and resurfacing of user context increases privacy risk and can expose sensitive information unexpectedly, especially in shared or mis-scoped chats.
