Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The skill instructs the agent to create and persistently update a local memory file containing user travel context and constraints without any disclosure, consent, retention policy, or minimization guidance. Even though the data appears travel-related, it can still include sensitive personal details such as nationality, visa status, travel dates, children, mobility needs, and health-related constraints, creating avoidable privacy and data-handling risk.
