Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill directly instructs users to fetch and run a third-party repository with `docker compose up` and proceed through setup, but it provides no security warning, trust boundary explanation, or verification guidance. In an agent setting, operational instructions like this can normalize execution of unreviewed infrastructure code, which could expose the host to malicious images, unsafe ports, secrets capture, or supply-chain compromise if the referenced project or its dependencies are tampered with.
