Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The skill explicitly instructs an agent to copy and rewrite files inside a user-provided `${PYOMNITS_PATH}` installation, which can modify local source trees without any warning, confirmation, backup, or validation of the target path. In an agent setting, this is dangerous because it normalizes direct filesystem changes and could overwrite existing code, corrupt an installation, or be redirected to an unintended path if variables are wrong or attacker-influenced.
