Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The skill explicitly instructs that detailed SAT-related user data be persisted under ~/sat/, including profile information, test dates, scores, mistakes, and study feedback, but provides no notice, consent flow, retention policy, or privacy safeguards. While this is not obviously malicious, it creates a real privacy risk because educational performance data and planning details are stored locally in a predictable location where other local users, backups, or tooling could access them unintentionally.
