Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The skill documents a fully permissive `--approve-all` mode that allows an ACP-driven agent to auto-approve every permission request, including writes or other sensitive actions, but it does not warn users about the security implications. In a headless agent-to-agent CLI, this materially increases the chance of unintended or unsafe autonomous actions because users may enable it in scripts without understanding the loss of human oversight.
