Missing User Warnings
Medium
- Confidence
- 90% confidence
- Finding
- The skill instructs the agent to start a background MCP server, automatically connect/register it, and enumerate its tools without waiting for user approval. That creates an implicit trust boundary crossing and can expose local project context, available capabilities, or network-reachable interfaces before the user has consented, which is especially risky because MCP tools may enable powerful file or system actions.
