Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The documented workflow instructs the agent to run commands that create and update files inside the repository, including graphify-out artifacts and cache data, without warning the user that the repo will be modified. In a security-sensitive or clean-working-tree context, this can lead to unintended filesystem changes, polluted diffs, accidental commits of generated artifacts, or disclosure of repository structure through persisted analysis outputs.
