Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The installer writes to or creates AGENTS.md automatically, and will also remove and replace an existing managed block, without any confirmation or explicit path selection by the user. Because AGENTS.md changes agent behavior persistently, this can silently alter future LLM behavior in the current directory, home directory, or OPENCLAW_WORKSPACE, which is a meaningful security and trust boundary even if the script's stated purpose is legitimate.
