Missing User Warnings
Medium
- Confidence
- 96% confidence
- Finding
- The `scan-tokens` feature parses gateway logs to extract token usage, but the skill does not warn that log files may contain sensitive metadata such as prompts, model names, request identifiers, timestamps, or other usage details. Without a privacy notice and scope clarification, users may unknowingly process or retain sensitive operational data.
