Missing User Warnings
Medium
- Confidence
- 96% confidence
- Finding
- The skill recommends `npx skills add <owner/repo@skill> -g -y`, which combines global installation with confirmation suppression and no accompanying warning about trust, scope, or review of third-party packages. In a skill-discovery workflow, this increases the chance that an agent or user installs unvetted remote code with system-wide effect and reduced friction for accidental or unsafe execution.
