Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The skill explicitly instructs creation of customer-specific files containing configuration, notes, and invoices, but it does not warn that customer data will be written to disk or require consent/minimization. This creates a real privacy and data-handling risk because personal or business-sensitive onboarding details may be stored locally in predictable paths without retention, access-control, or sanitization guidance.
