Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The template explicitly encourages storing sensitive remote-access metadata such as host identifiers, usernames, ports, and tunnel commands in persistent local memory files, but provides no warning, minimization guidance, or handling requirements. In a remote desktop skill, this is more dangerous because these details can reveal internal network structure and facilitate lateral movement or unauthorized access if the memory store is exposed.
