Missing User Warnings
High
- Confidence
- 96% confidence
- Finding
- The skill explicitly promotes exposing arbitrary local CLI sessions through a public tunnel, but the description and usage guidance do not provide a prominent warning about the risk of internet exposure, command execution, data leakage, or unintended sharing of an interactive terminal. In this context, the omission is dangerous because the skill can publish highly privileged local shells and developer tools, and the stated protections (URL secrecy and short authentication window) are not a sufficient substitute for clear user consent and risk communication.
