Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The skill explicitly instructs the agent to search complete historical session logs, including older and parent conversations, but does not include any user-facing privacy warning, consent check, or minimization guidance. This creates a real privacy risk because a user may ask an innocuous question without realizing the agent is authorized to inspect broad prior conversation history that may contain sensitive data from unrelated contexts.
