Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill description does not clearly warn users that submitting a message will cause the system to fetch external URLs, transform the content, write files into a repository, and push changes to GitHub automatically. In this context, that omission is security-relevant because the skill performs network access and repository modification based on user input, which can lead to unexpected disclosure, persistence of untrusted content, or unintended commits.
