Missing User Warnings
Medium
- Confidence
- 90% confidence
- Finding
- The `--auto` flow modifies host plugin loading and explicitly enables `hooks.allowPromptInjection=true` and `hooks.allowConversationAccess=true`, which expands the agent's access to prompts and conversation content. While the behavior is described, it is not presented as a clear warning/consent boundary before the command, so operators may enable sensitive hooks without appreciating the security and privacy implications.
