Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The skill explicitly documents a `create_comment` command that performs a write operation against a remote Yunxiao system, but it does not warn that this action modifies shared project data or recommend confirmation before use. In an agent setting, missing guardrails around state-changing operations can lead to unintended comments being posted to production work items, causing workflow disruption, audit noise, or accidental disclosure.
