Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill explicitly instructs the agent to write generated `.puml` files into the user's workspace without requiring prior user confirmation or presenting a clear warning that files will be created or modified. In agentic environments, silent workspace writes can surprise users, overwrite existing content, or be chained with other behaviors to stage artifacts the user did not knowingly authorize.
