Missing User Warnings
Medium
- Confidence
- 91% confidence
- Finding
- The skill explicitly instructs the agent/user to create or modify local configuration and operational files such as AGENTS.md and HEARTBEAT.md, which changes system behavior and persistence without any explicit warning, confirmation gate, or scope limitation. In a security context, silent modification of local config and agent-control files can alter execution policy, persistence, and autonomy in ways the user may not fully understand.
