Missing User Warnings
Medium
- Confidence
- 87% confidence
- Finding
- The skill documents a destructive deletion command, `file:rm --path <p>`, without requiring confirmation, dry-run behavior, or explicit user authorization. In an agent context, broad triggers and procedural guidance can lead to accidental or over-broad deletion of project files or directories, especially if path values are inferred from ambiguous user requests.
