Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The skill explicitly states it will create `~/bass/` on first interaction, but it does not say this will only happen after user consent or with a clear notice. Unannounced filesystem writes in a user's home directory violate least surprise and can create privacy, trust, and policy issues even if the directory is only used for legitimate practice data.
