Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The skill advertises that completed tasks are automatically saved to ClawVault, but the description does not provide a prominent privacy warning about what task descriptions and notes may be transmitted or persisted externally. In an agent context, task titles and notes can contain sensitive data such as internal project names, credentials-in-context, customer details, or research notes, so implicit auto-sync increases the risk of unintended data exfiltration.
