Missing User Warnings
Medium
- Confidence
- 97% confidence
- Finding
- The skill explicitly instructs the agent to automatically install the `universal-task-os` dependency whenever it is missing, without requiring user confirmation or presenting any trust warning. Automatic dependency installation expands the attack surface, can introduce unreviewed code into the runtime, and is especially risky because the installed skill would gain influence over subsequent task execution.
