Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The skill directs the agent to read and update a persistent local memory file containing user travel context, constraints, and potentially sensitive personal details, but it does not require a clear user-facing disclosure or consent flow for that storage. This creates a privacy risk because users may unknowingly have personal relocation, health, family, visa, or work information retained across sessions on disk.
