Missing User Warnings
Medium
- Confidence
- 88% confidence
- Finding
- The README explicitly promotes networked skill search, downloading/installing skills, and automatic skill creation, but it does not warn users that these actions may transmit prompts/data to external services or modify the local/global environment. In a skill whose purpose is to discover and install code-like extensions, the lack of consent, trust-boundary disclosure, and safety guidance increases the chance of unintended external data exposure or installation of untrusted components.
