Missing User Warnings
Medium
- Confidence
- 91% confidence
- Finding
- The skill instructs the agent/user to run multiple shell commands that modify authentication, model configuration, and service state, including non-interactive onboarding with secret-bearing CLI flags and gateway restarts, without any explicit warning, confirmation, or rollback guidance. In an agent setting, this can cause unintended reconfiguration, service disruption, or credential exposure in shell history/logs if executed automatically or copied blindly.
