Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The skill explicitly recommends an `open-preview` flow that automatically opens a browser for the human without describing any consent, prompt, or safety check. Even though this is a local action, triggering browser launches from agent workflows can surprise users, create clickjacking/social-engineering opportunities, and normalize unsafe UI side effects.
