Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The README instructs users to enable automated extraction via HEARTBEAT without clearly warning that local memory content will be periodically read and persisted into a SQLite database. In an agent skill context, silent or insufficiently disclosed collection and storage of potentially sensitive notes, configuration details, or security-related memory increases privacy and data retention risk, especially if users assume the feature is lightweight but not persistent.
