Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill explicitly supports writing to shared documentation and requesting publication to a public vault, but it does not clearly warn users that these actions can expose note contents to all users of the instance or to the public. In a memory-sharing skill, agents may store sensitive prompts, credentials, internal notes, or user data; without an explicit disclosure warning, users and downstream agents can mistakenly treat the system as private and leak data unintentionally.
