Missing User Warnings
Medium
- Confidence
- 91% confidence
- Finding
- The session-start routine instructs the agent to automatically read multiple local memory files before responding, without requiring explicit user consent or warning that those files may contain sensitive workspace data. In environments where file access is powerful, this can lead to unnecessary exposure of private project context and normalization of implicit workspace-wide data access.
