Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The skill explicitly instructs the agent to collect user preferences and store reusable travel knowledge in a local vault, but it provides no user-facing disclosure, consent step, or retention guidance. This creates a real privacy risk because itinerary details, preferences, and potentially sensitive travel patterns may be persisted locally without the user realizing their data is being written and reused later.
