Missing User Warnings
Medium
- Confidence
- 90% confidence
- Finding
- The skill directs users to copy images from a restricted directory into an allowed directory without clearly warning that this creates a second local copy of potentially sensitive user data. This increases data persistence and exposure risk, especially if the media directory is more broadly accessible, retained longer, or reused by other tools.
