Missing User Warnings
Medium
- Confidence
- 89% confidence
- Finding
- The skill explicitly persists user preferences, app history, dislikes, and wishlist data under `~/apps/` but does not instruct the agent to obtain user consent, disclose retention, or minimize stored data. Even though the storage is local and not obviously exfiltrated, this creates a privacy risk because sensitive behavioral preferences may be retained longer than the user expects and could be accessed by other local processes or users on the same system.
