Missing User Warnings
Medium
- Confidence
- 97% confidence
- Finding
- The skill instructs agents to write conversation content into a shared file used by multiple Kiro instances, but it does not warn users that prompts, responses, or sensitive context may be persisted and exposed across environments. This creates a real confidentiality and data-leakage risk, especially if one instance handles secrets, private user data, or instructions that another instance should not automatically inherit.
