Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill includes concrete load-testing instructions that default to 100 concurrent WebSocket connections for 60 seconds without any safety warning, scope limitation, or authorization check. In a security-testing skill, this can easily be used against production or third-party endpoints, causing service degradation, quota exhaustion, or accidental denial-of-service even if the author's intent is legitimate testing.
