Missing User Warnings
Medium
- Confidence
- 81% confidence
- Finding
- The skill exposes numerous destructive and privilege-altering administrative operations such as deleting users, deleting groups, wiping devices, turning off 2-Step Verification, making users admins, and revoking tokens, but it does not consistently frame them with safety guardrails, confirmation requirements, or explicit risk warnings. In an agentic context, sparse warnings increase the chance of accidental misuse, overbroad execution, or unsafe automation against a highly privileged admin surface.
