Missing User Warnings
Medium
- Confidence
- 89% confidence
- Finding
- The script duplicates authentication and model configuration files from the main agent into every team and member agent directory without explicit user consent, warning, or least-privilege scoping. In a multi-agent architecture, this broadens credential exposure and means any compromised or less-trusted subagent may inherit access intended only for the primary agent, increasing blast radius.
