Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The skill directs the agent to enable automatic plugin installation globally on the local Alibaba Cloud CLI without explicit user consent or warning. This changes local execution behavior and can cause future commands to fetch and install software automatically, increasing supply-chain and unintended-code-execution risk beyond the immediate task.
