Description-Behavior Mismatch
Medium
- Confidence
- 91% confidence
- Finding
- The fetch-only mode exports pending review content to a local JSON file, which can include sensitive, regulated, or confidential user-submitted content. In a moderation skill, bulk export for offline handling increases data-exfiltration and retention risk, especially because the file is written in plaintext without access controls, redaction, encryption, or an explicit warning.
