Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The code persists user-supplied error details and captured stack traces to a local JSON file, which can include secrets, file paths, tokens, request contents, or other sensitive diagnostics. In an agent context, these records may aggregate sensitive prompts, tool outputs, and runtime failures over time, increasing the chance of unintended disclosure if the file is read, exported, or committed.
