Missing User Warnings
Medium
- Confidence
- 96% confidence
- Finding
- The skill explicitly states it extracts the last 300 messages from every agent session and writes them into persistent markdown files, but it does not present any warning about the privacy and retention implications of capturing all user↔agent messages. This is dangerous because users may disclose sensitive information under the assumption of ephemeral chat behavior, while the skill silently creates durable plaintext copies that can later be read, reused, or exposed to other tools and agents.
