Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill explicitly instructs the agent to load a persistent operator profile at session start, silently adapt behavior, and write updated behavioral data at session end without a clear consent or notice flow. Even if the author claims the data is local and derived, this is still persistent behavioral profiling across sessions, which creates privacy, transparency, and potential misuse risks if the workspace is shared, compromised, or repurposed by other components.
