Missing User Warnings
Medium
- Confidence
- 88% confidence
- Finding
- The skill enables persistent background jobs that can post messages to a Discord channel later, but it does not require explicit user confirmation, visibility into persistence, or safeguards against accidental long-lived posting. This is dangerous because users may unintentionally authorize recurring or delayed actions that continue after the original conversation, leading to unwanted channel spam, confusion, or abuse if the request was ambiguous or maliciously framed.
