Missing User Warnings
Medium
- Confidence
- 86% confidence
- Finding
- The README states that audit reports are written to <skill-dir>/.audit-report.md and .audit-report-prev.md, but it does not clearly warn that normal use will create or overwrite files in the target skill directory. In a security-auditing context, unexpected filesystem writes can surprise users, destroy prior reports, or modify repositories that were assumed to be read-only, which is especially risky because the skill otherwise emphasizes a mostly read-only audit workflow.
