Missing User Warnings
Medium
- Confidence
- 89% confidence
- Finding
- The skill instructs the agent to automatically write user-derived information into persistent files during normal conversation and on a schedule, without clear notice or explicit consent boundaries. In a memory-management skill, that context makes the issue more dangerous because the data being written is specifically personal history, preferences, projects, and corrections, which can accumulate into sensitive profiling.
