Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill explicitly instructs the agent to create and update a persistent local memory file containing user travel preferences, constraints, and potentially sensitive context without any notice, consent, retention limits, or access controls. Even though the data is travel-related rather than highly regulated financial data, it can still reveal behavioral patterns, family status, mobility needs, dietary restrictions, and future travel plans, making this a real privacy and data-handling issue.
