Description-Behavior Mismatch
Medium
- Confidence
- 86% confidence
- Finding
- The script silently initializes a Git repository inside the ChromaDB directory and commits index contents, creating an undocumented persistence and history layer. This can retain sensitive document-derived data longer than expected and expands the skill's side effects beyond ordinary indexing/search, increasing disclosure and recovery risks if the DB directory is accessed later.
