Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The skill includes write and destructive commands such as like, favorite, comment, delete, and post, but it does not require explicit user confirmation or a safety check immediately before executing account-changing actions. In an agent setting, this increases the risk of unintended social actions, content deletion, or posting on a live account due to misunderstanding, prompt injection, or ambiguous user intent.
