Missing User Warnings
Medium
- Confidence
- 96% confidence
- Finding
- The skill is explicitly designed to persist user context across sessions, but it provides no privacy notice, retention policy, or guidance to avoid storing sensitive personal data. In a memory skill, this omission is dangerous because agents are encouraged to collect and retain cross-session user information by default, creating risk of unauthorized profiling, over-collection, and privacy violations.
