Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill instructs the user to append a hidden OADP marker into a workspace file read on boot, modifying local state in a way that affects agent behavior and discoverability without any warning, consent, or rollback guidance. Because the marker is specifically designed for scanners to detect and influence future interactions, this creates an unnecessary persistence and trust-signal injection risk in the local workspace.
