Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The skill explicitly instructs the agent to overwrite the active soul.md and modify IDENTITY.md, but it does not require an explicit warning or confirmation before performing these persistent file changes. In this context, a user may trigger what appears to be a simple persona switch without understanding that it permanently alters local configuration files and creates or overwrites backups, which creates a real integrity and recoverability risk.
