Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill requires running configuration-changing CLI commands on every invocation, including read-only flows, and does so without requiring explicit user consent or clearly warning that local CLI state will be modified. This can unexpectedly alter the user's environment, plugin state, and client configuration, creating side effects outside the requested task and expanding the blast radius if the agent is triggered unintentionally.
