Missing User Warnings
Medium
- Confidence
- 88% confidence
- Finding
- The skill explicitly enables execution of arbitrary Python and bash in a persistent remote sandbox, including helper functions that can call external services and connected apps. Even if intended for legitimate automation, presenting these capabilities without strong safety gates, user-consent requirements, or warnings about destructive/system-impacting actions materially increases the chance of harmful execution, data exfiltration, or lateral abuse through connected accounts.
