Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The skill explicitly documents raw proxy access with mutating HTTP methods like POST, PUT, PATCH, and DELETE without requiring confirmation or warning that these operations can alter or destroy API Gateway configuration. In a high-impact administrative service like API Gateway, this increases the chance that an agent performs destructive or irreversible changes based on ambiguous prompts.
