Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The skill documentation instructs users to run alerting and cron setup commands that can send notifications and modify scheduled tasks, but it does not clearly warn about these side effects or require explicit confirmation. In an agent-skill context, that increases the chance of unintended outbound messaging or persistence-like behavior being triggered by a user or automation without informed consent.
