Missing User Warnings
Medium
- Confidence
- 91% confidence
- Finding
- The skill instructs users to perform direct MCP calls, OAuth authentication, configuration edits, daemon control, and stdio execution, but it provides no safety guidance about credential handling, trust boundaries, or the fact that these actions may modify local config or interact with remote systems. In this context, the omission is risky because the skill normalizes potentially sensitive operations without warning users to verify endpoints, review arguments, or avoid exposing secrets in command lines and config files.
