Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill explicitly configures unattended daily updates that modify the Clawdbot installation and all installed skills, including global package updates and bulk skill updates. Even though this appears intended for convenience rather than abuse, automatic code-changing behavior without prominent warnings, approval gates, rollback guidance, or pinning increases supply-chain and stability risk because newly published upstream changes are applied automatically.
