Missing User Warnings
Medium
- Confidence
- 70% confidence
- Finding
- The script modifies the user's agent workspace by downloading and writing a remote file without any prior user-facing notice or confirmation. This reduces informed consent and makes silent workspace modification easier, which increases the risk of unexpected or malicious skill content being installed through a trusted-looking installer.
