Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- This skill documents `opencli plugin install github:user/repo` and `opencli install <name>` auto-install flows that can fetch and execute third-party code, but it does so without an explicit safety boundary, trust model, or confirmation requirement. In an agent setting, that omission can normalize executing unreviewed code from git or package managers, leading to arbitrary code execution, supply-chain compromise, or installation of malicious tooling.
