Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The README explicitly promotes unauthenticated local-network control of Roku devices, including power, app launch, playback, and text input, but does not warn that using the skill can immediately affect active devices, interrupt viewing, or inject on-screen input into the wrong context. In an agent skill context, missing safety/consent guidance increases the risk of unintended or unauthorized control of household devices, especially because the protocol requires no authentication.
