Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill explicitly instructs that the agent can invoke a deploy hook with curl, which causes a state-changing external action without requiring an explicit user confirmation step at the point of execution. In an agent context, this is dangerous because a deployment can alter production behavior, trigger outages, consume resources, or roll out unintended code based solely on the presence of a hook URL in the environment.
