Missing User Warnings
Medium
- Confidence
- 91% confidence
- Finding
- The script persistently writes debate state, participant identifiers, votes, message IDs, and full debate/judge content to local files under the user's home directory and to archive/log files, but provides no user-facing disclosure, consent flow, retention control, or protection checks. In a debate skill, these records can contain sensitive personal data, private group context, and opinion content; if the host machine or account is shared or compromised, this creates avoidable confidentiality and privacy risk.
