Missing User Warnings
Medium
- Confidence
- 91% confidence
- Finding
- The skill explicitly states it logs every tool invocation with context and creates audit log storage, but it provides no warning, minimization guidance, or controls for sensitive data retention. Tool inputs, reasons, and surrounding context can contain secrets, personal data, or proprietary prompts, so silent persistence increases the risk of accidental exposure, over-retention, and secondary misuse.
