Missing User Warnings
Medium
- Confidence
- 86% confidence
- Finding
- The script transmits user-supplied message content to a remote host over SSH without any user-facing disclosure, confirmation, or logging, which can cause unintended exfiltration of sensitive data entered as the message argument. In this skill context, the command is explicitly designed to bridge to a remote operator machine, so silent remote transmission is more dangerous because users may treat it as a local helper while it actually sends content off-host.
