Missing User Warnings
Medium
- Confidence
- 89% confidence
- Finding
- The skill documentation explicitly instructs the agent to run install, update, and publish commands that can change local files, upgrade dependencies, or modify remote registry state, but it provides no safety constraints, confirmation requirements, or warnings about those side effects. In an agent context, this increases the risk of unintended package installation, destructive updates, or accidental publication of local content, especially when combined with flags like --all, --force, and --no-input.
