Missing User Warnings
Medium
- Confidence
- 96% confidence
- Finding
- The skill explicitly states it reads from the memory/ directory and writes generation history to memory/cross-border-history.md, but it does not disclose this persistence behavior to the user or describe consent, retention, or scope limits. This creates a privacy and data-governance risk because user inputs, preferences, and potentially commercially sensitive product research could be silently persisted across sessions.
