Missing User Warnings
Medium
- Confidence
- 90% confidence
- Finding
- The register flow persists sensitive session metadata including session_key, delivery_channel, delivery_account_id, delivery_target, and optional workspace/notes into a registry file without any visible consent prompt, masking, or file-permission hardening in this code path. In the context of a session recovery/monitoring skill, storing these values may be functionally necessary, but if the registry is readable by other local users or tooling it can expose credentials or routing metadata that could enable session hijacking, message misdelivery, or privacy leakage.
