Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill repeatedly states it will read staged diffs, file paths, and branch-name context to generate a commit message, but it does not clearly and prominently disclose that this repository content may be transmitted to the AI for analysis. That can expose proprietary code, secrets accidentally staged in diffs, internal issue IDs, or sensitive branch metadata without the user's informed consent.
