Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The skill explicitly instructs users to enable full HTTPS man-in-the-middle interception and install a locally generated CA into the system trust store, but it does not present clear warnings about the security and privacy consequences. Trusting a local CA broadly expands the host's attack surface: compromise or misuse of that CA key would allow silent interception of other TLS traffic and may normalize unsafe trust-store modification practices.
