Missing User Warnings
Medium
- Confidence
- 90% confidence
- Finding
- The skill explicitly directs the agent to persist notes in `~/homepod/memory.md` without requiring user disclosure, consent, retention limits, or any guidance on minimizing sensitive content. In a home automation context, those notes may include device inventory, network details, protected rooms, and operational preferences, creating a privacy and security risk if stored unexpectedly or accessed by other processes.
