Missing User Warnings
Medium
- Confidence
- 88% confidence
- Finding
- The skill instructs the agent to run `mwf-bench audit --path /path/to/wp` for local site audits but does not require an explicit user warning or consent that a paid external API will be contacted and that plugin/theme inventory derived from the local WordPress installation may be transmitted off-host. In a site-audit context, that omission can lead to unintended disclosure of environment details and unexpected quota or billing usage.
