Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The skill explicitly instructs agents to invoke a shell-executed external CLI for coding tasks, but provides no safety guidance about command execution side effects, prompt/argument injection risks, or trust boundaries around the repo and prompt contents. In an agent setting, normalizing direct exec as the default path increases the chance that untrusted task data or repository content will be passed into shell commands or a powerful coding tool without adequate review.
