Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill explicitly instructs the agent to execute actions, configure tools, write code, and run scripts, but it provides no requirement for user confirmation, safety checks, or disclosure that files and environment state may be modified. In an agent setting, this creates a real risk of unauthorized or unexpected changes to local projects, credentials, CI/CD configuration, or other resources, especially because the skill frames action-taking as the default success condition.
