Missing User Warnings
Medium
- Confidence
- 89% confidence
- Finding
- The guidance explicitly recommends copying files into an app-private `/data/data/...` directory once 'root authorization' is obtained, but it does not require explicit per-action user confirmation, scope limitation, or warn about the sensitivity of privileged filesystem access. In a skill that automates MCP-driven project and asset workflows, this can normalize use of root to bypass normal storage boundaries and may lead to unauthorized file access, data exposure, or accidental modification of protected app data.
