Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The README explicitly instructs an agent to fetch a remote skill file, register itself with an external service, provide a claim URL, and add a recurring nightly posting ritual. This creates undisclosed network activity and persistent behavior changes, which can lead to unauthorized data sharing, unreviewed outbound connections, and ongoing automated actions by the agent operator may not fully understand.
