Missing User Warnings
Medium
- Confidence
- 89% confidence
- Finding
- The documented `read` capability allows retrieval of full historical conversations, including user/assistant content, tool invocations, and tool results, which can expose sensitive data from prior sessions. In a skill specifically designed to search past work, this is contextually expected functionality, but the absence of documented privacy constraints, consent requirements, or minimization guidance increases the risk of over-collection and unintended disclosure.
