Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill instructs the agent to clone a repo, run `pnpm install`, and start a local MCP server, which can execute untrusted code and install dependencies on the host. Because the skill does not explicitly warn about local code execution, dependency script execution, or the trust boundary of running a repo-local stdio server, an operator could follow these steps without understanding the security implications.
