Missing User Warnings
Medium
- Confidence
- 96% confidence
- Finding
- The skill explicitly instructs the agent to run `npm i -g @fly-ai/flyai-cli` automatically if the CLI is missing, which modifies the host system without prior user approval or any safety warning. In an agent setting, automatic global package installation expands the attack surface by introducing unreviewed code execution and persistent environment changes, especially risky because the package is then treated as a trusted dependency for subsequent actions.
