Description-Behavior Mismatch
Medium
- Confidence
- 91% confidence
- Finding
- The design adds persistent local session storage under a user home directory and stores full state/history, but the skill metadata does not disclose this behavior. In a multi-tenant or shared-host setting, undocumented persistence increases the chance of sensitive prompts, plans, tool outputs, or identifiers being retained longer than expected and accessed by other processes, backups, or operators.
