Missing User Warnings
Medium
- Confidence
- 86% confidence
- Finding
- The README explicitly advertises capabilities to post comments, replies, and publish posts to an external Xiaohongshu account, but it does not warn that these actions modify live third-party platform content or require explicit user confirmation. In an agent skill context, this omission increases the risk of unintended real-world actions, account misuse, spam, or reputational damage if the skill is invoked casually or automatically.
