Missing User Warnings
Medium
- Confidence
- 96% confidence
- Finding
- The skill explicitly stores cross-session 'critic memory' in a persistent SQLite database without any visible user notice, consent flow, retention limit, or review/deletion mechanism. In practice, this can lead to unintended retention of sensitive user inputs across sessions and creates a privacy/security risk if later prompts, agents, or operators can access prior stored data.
