Missing User Warnings
Medium
- Confidence
- 90% confidence
- Finding
- The skill explicitly instructs the agent to install community skills into a local mini-program project and later run setup steps that change project state. Because the documentation does not prominently warn that installation can modify code, dependencies, configuration, and potentially introduce third-party code into the user's project, a user may authorize impactful actions without informed consent.
