Missing User Warnings
Medium
- Confidence
- 90% confidence
- Finding
- The skill instructs the agent to publish the generated skill to an external service (`clawhub publish`) without an explicit warning that local project content, metadata, or residual sensitive material may be transmitted off-host. In a skill specifically designed to distill local projects, this omission increases the risk of accidental data exfiltration if scanning or validation is incomplete or misunderstood.
