Missing User Warnings
Medium
- Confidence
- 90% confidence
- Finding
- The release notes document environment-variable overrides that can disable onboarding checks globally or per-repo, which weakens the guard's security controls and creates an easy bypass path if inherited shell environment or caller-controlled env is present. Although framed as an intentional escape hatch for testing or approved use, a blanket override like `LDM_GUARD_SKIP_ONBOARDING=1` materially reduces protection and is especially risky because the notes do not strongly emphasize the security consequences at the point of use.
