Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The skill instructs the agent to execute `node analyze-dom.js <URL>` directly on a user-supplied URL, which causes external network access and local command execution behavior without any warning, validation, or restriction. In an agent environment, this can be abused to trigger requests to internal services, sensitive endpoints, or attacker-controlled infrastructure, and the skill gives no safeguards around allowed schemes, hosts, or execution boundaries.
