Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The skill explicitly describes automatically writing oversized tool results to local disk and returning a file path, but it does not warn that tool output may contain secrets, personal data, or other sensitive content that will now persist beyond the conversation. This increases exposure through local file access, backups, logs, and later reuse of spilled files, especially because previews and audit logs may also duplicate sensitive content or metadata.
