Context-Inappropriate Capability
Medium
- Confidence
- 93% confidence
- Finding
- The skill explicitly instructs creation of a persistent `dev-mentor-projects.json` file in the working directory to retain cross-session state, including project details, issues, todos, and server information. For a conversational learning companion, this is more data retention than is strictly necessary and creates privacy and data-handling risk, especially if the working directory is shared, synced, or later exposed.
