Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill instructs the agent to create and maintain a persistent file in the user's home directory containing sensitive travel context such as passport/nationality, budget, mobility, and other personal constraints, but it does not require explicit user consent or provide a retention notice. Persistent storage of personal data without clear notice and opt-in increases privacy risk, can surprise users, and may expose sensitive information to other tools or future sessions.
