Missing User Warnings
Medium
- Confidence
- 86% confidence
- Finding
- The skill explicitly instructs downloading generated files locally and delivering them to the user, but it does not warn that this causes local file writes or that the downloaded artifacts may contain sensitive, malicious, or unexpected content. Because outputs come from an external autonomous agent, treating them as safe by default increases the risk of unsafe storage, accidental exposure, or mishandling of untrusted files.
