Missing User Warnings
Medium
- Confidence
- 97% confidence
- Finding
- The skill provides concrete offensive security testing steps, including brute-force attempts, injection payloads, force browsing, and method tampering, but does not clearly require prior authorization, scope validation, rate limiting, or warnings about service disruption and legal impact. In a reusable agent skill, this omission is dangerous because it can normalize or facilitate testing against unintended targets and can cause account lockouts, data modification attempts, or operational disruption.
