Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The skill explicitly enables real-world smart-home actions such as controlling lights, thermostats, locks, and timers, but it provides no safety guidance, confirmation requirements, or warning that these commands can affect physical devices and household security. In an agent setting, natural-language passthrough like `alexacli command` materially increases risk because a mistaken, malicious, or context-confused invocation could unlock or alter physical systems.
