Missing User Warnings
Medium
- Confidence
- 88% confidence
- Finding
- The fallback LocalStore persists tracked package data, including tracking numbers, courier metadata, package names, status history, timestamps, and locations, to a plaintext JSON file under the user's home directory without any consent flow, retention policy, or access controls. In a logistics-monitoring skill, this data can reveal purchasing activity, movement patterns, and home/work locations, so silent local persistence increases privacy risk if the host is shared, backed up, or otherwise accessed by other local processes/users.
