Missing User Warnings
Medium
- Confidence
- 96% confidence
- Finding
- The skill explicitly instructs the agent to update USER.md and MEMORY.md with 'deep psychology,' emotional context, and relationship dynamics, creating a persistent profile of sensitive personal data without consent, minimization, or retention limits. In an agent skill, this is dangerous because it normalizes long-term storage of inferred psychological traits that users may never realize are being recorded, increasing privacy, misuse, and secondary-exposure risk.
