Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill explicitly instructs the agent to install a global npm package (`npm i -g @fly-ai/flyai-cli`) automatically if the CLI is missing, without requiring user consent, provenance verification, or integrity checks. This creates a supply-chain and environment-modification risk: a skill invocation can trigger code installation and persistent system changes on the host.
