Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The changelog explicitly advertises that the skill will proactively message users immediately after installation, but it does not mention any prior consent, opt-in flow, rate limiting, or ability to disable the behavior. This creates a real autonomy and UX risk because the agent is designed to initiate interaction unprompted, which can surprise users, violate platform expectations, or be used for manipulative engagement patterns.
