Missing User Warnings
Medium
- Confidence
- 88% confidence
- Finding
- The README recommends `subagents.allowAgents: ["*"]`, which grants an agent the ability to discover and spawn any other agent without documenting trust boundaries, privilege separation, or abuse scenarios. In a multi-agent system, this can enable lateral movement, unintended delegation of sensitive tasks, and amplification of a compromised or misconfigured agent's access.
