Description-Behavior Mismatch
Medium
- Confidence
- 90% confidence
- Finding
- The CLI persists per-user usage statistics in ~/.hermes/task-cost-history.json even though the skill is presented primarily as a pre-task cost estimator. While it does not store full task text, undisclosed persistent storage creates a privacy and data-minimization issue because usage metadata is retained across sessions without explicit opt-in or clear notice.
