Missing User Warnings
Medium
- Confidence
- 90% confidence
- Finding
- The README advertises destructive actions like `tasks delete <id>` and potentially high-impact actions like `flows trigger <id>` without any warning, confirmation guidance, or mention of least-privilege API key usage. In an agentic/natural-language context, this increases the chance that ambiguous prompts, prompt injection, or user misunderstanding could cause irreversible task deletion or unintended workflow execution.
