Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill explicitly instructs use of `claude --permission-mode bypassPermissions`, which disables normal permission safeguards for an external coding agent. In a skill whose purpose is to delegate repository work, this materially increases the chance of unintended file modification, secret exposure, destructive commands, or execution of unreviewed actions without any warning, gating, or justification tied to a trusted sandbox.
