Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- This skill explicitly configures unattended daily updates that modify both Clawdbot and all installed skills, but it does not prominently warn the user about the risks of automatic changes to their local environment. Automatically pulling and applying updates on a schedule expands the trust boundary to remote registries and package sources, and can introduce unexpected breakage or supply-chain compromise without a fresh approval step.
