Missing User Warnings
Medium
- Confidence
- 96% confidence
- Finding
- The skill explicitly advertises automatic confirmation of installs using --force but does not warn the user that this may bypass safety prompts, including installs flagged as suspicious. That creates a meaningful trust and consent problem: a user may invoke a routine installer while the agent silently overrides protective checks and proceeds with potentially unsafe code.
