Missing User Warnings
Medium
- Confidence
- 90% confidence
- Finding
- The runbook explicitly stores the user's raw input in an internal execution log and persists that log to a local file if writes are available. In a travel-booking skill, raw queries can contain sensitive personal and trip data such as names, phone numbers, passport or visa details, booking references, and itineraries, so retaining them without clear minimization, consent, redaction, or retention controls creates a real privacy and data-exposure risk.
