Missing User Warnings
Medium
- Confidence
- 91% confidence
- Finding
- The skill explicitly states that it will automatically install the `apriltag_detection` library using `gettool` if the dependency is missing, but it does not warn the user that invoking the detector may trigger network access and modify the local environment. In an agent setting, silent dependency installation expands the trust boundary and can lead to unexpected package downloads, supply-chain risk, or unauthorized changes on the host system.
