Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The skill instructs users to run local setup and startup scripts from a cloned repository without any warning that these commands execute repository-controlled code and can install dependencies, start services, or modify the local system and workspace. In an agent-skill context, this increases the risk of unsafe code execution because the document normalizes direct execution of unreviewed scripts from an external repo.
