Missing User Warnings
Medium
- Confidence
- 90% confidence
- Finding
- The skill explicitly advertises high-impact capabilities including file write/move, network requests, and command execution, but does not describe any guardrails such as user confirmation, path restrictions, allowlists, or consent before destructive or external actions. In an automation skill, these capabilities materially increase the chance of unsafe workflows causing data loss, unintended system changes, or exfiltration if invoked from ambiguous or attacker-influenced inputs.
