Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill explicitly instructs the agent to write to files in the user's home directory, including ~/price-history.jsonl and ~/commands.json, without warning the user that local state will be created or overwritten. This is dangerous because an autonomous skill can persist data, alter future agent behavior, and clobber existing files in a sensitive per-user location.
