Natural-Language Policy Violations
Medium
- Confidence
- 92% confidence
- Finding
- The skill explicitly says the agent may suggest or run `bes language zh` based on the user's language being Chinese, but it does not require explicit user consent before changing a persistent local configuration. Because this writes to a user-level config file and changes future behavior beyond the current request, inferred language alone is not sufficient authorization and can result in unwanted persistent preference changes.
