Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The skill exposes numerous state-changing and destructive operations such as create, update, delete, approve, cancel, check-in/out, archive, and deliver actions, but the documentation provides no guidance to require explicit user confirmation before executing them. In an LLM-agent context, this increases the risk of accidental or prompt-induced modifications to workplace data, including bookings, visitor records, maintenance workflows, moves, mail handling, and user/building records in a real enterprise tenant.
