Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- This script copies multiple potentially sensitive local artifacts into a cloud-synced Proton Drive folder, including launch agent definitions, application config, memory files, agent files, and generated content, without any interactive confirmation, explicit warning, or scoping controls. In a backup skill, exfiltration to cloud storage is part of the functionality, but the lack of user-visible disclosure and selective opt-in increases the risk of unintentionally transmitting secrets, internal prompts, credentials, or personal data.
