Missing User Warnings
Medium
- Confidence
- 96% confidence
- Finding
- The skill explicitly instructs the agent to collect exact location and maintain persistent filesystem logs across conversations, but it does not disclose retention scope, minimization rules, access boundaries, or user consent requirements. This creates a privacy and data-handling risk because sensitive profile data about location, habits, and potentially commercial activity could be stored longer than necessary or reused in ways the user does not expect.
