The audit reads local product-marketing files without per-run consent
Source references: 1Before every ASO audit, the Skill instructs the agent to check and read marketing context from three conventional locations. Such files may contain unreleased positioning, competitive strategy, customer segments, or business metrics; supplying a store URL does not necessarily authorize access to those local materials.
The contents enter the agent's processing context and may be reflected in the audit. Internal strategy could be indirectly disclosed if the session or report is shared. The supplied evidence does not show an instruction to upload the original file to a third party.
Before any audit, the Skill actively checks for and reads marketing context from one of three workspace locations. If that file contains unreleased positioning, customer, or business information while the user supplied only a store link, this expands local-data access. The stated purpose is to avoid repeat questions, and no upload or modification is instructed, but users can require use of explicitly supplied material only or prior approval of the file.
## Before Auditing**Check for product marketing context first:**If `.agents/product-marketing.md` exists (or `.claude/product-marketing.md`, or the legacy `product-marketing-context.md` filename, in older setups), read it before asking questions. Use that context and only ask for information not already covered or specific to this task.