Missing User Warnings
Medium
- Confidence
- 85% confidence
- Finding
- The script persists retrieved customs trade records to a task result file via append_result_data() and later exposes the file path/URL in output, but it provides no consent notice, retention policy, access control indication, or data-minimization guardrails. In this skill's context, the data includes trade order details and business contact information, so silent local persistence increases the risk of unintended disclosure, over-retention, or secondary access by other users/processes on the host.
