Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill explicitly directs the agent to automatically inspect the host environment and execute shell commands before obtaining clear user consent or giving an upfront warning. Even though the listed commands are relatively low risk, automatic local probing reveals system details and normalizes unsandboxed command execution, which can violate user expectations and become dangerous if the workflow or referenced steps later expand to more invasive commands.
