Missing User Warnings
Medium
- Confidence
- 81% confidence
- Finding
- The skill explicitly instructs saving delegated model output to a temp file, but provides no requirement to obtain user consent, classify content sensitivity, or warn about local persistence. Because this skill handles long-form user-facing text that may contain sensitive user data, writing responses to disk can create unintended retention and exposure risks through temp-file access, backups, logs, or later reuse.
