Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill explicitly instructs creation and execution of a Windows JScript file that can perform file access, shell command execution, WMI queries, and HTTP communication, but it provides no user-facing warning or consent guidance about system modification, data access, or network egress. In an agent skill context, this materially increases the risk of unsafe automation, unintended exfiltration, or destructive actions being carried out without the operator understanding the consequences.
