Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill explicitly instructs the agent to run autonomous background tasks and persist state to workspace files without any consent, scoping, or safeguards. In practice, this can cause unintended modification of user data, surprise actions, and accumulation of sensitive context in files the user may not expect the agent to create or update.
