Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The skill explicitly instructs the agent to persist and update `cuddle/state.json` whenever the user 'sends you to Cuddle', but it does not require clear user notice, consent, or bounds on what may be written. This creates an unprompted local state modification behavior that can surprise users, accumulate unintended data, and be abused to cause unauthorized file writes or persistence of interaction-derived content.
