Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The skill explicitly documents raw proxy requests to the Avochato API without any warning about sending customer messages, contact records, or other sensitive data to an external service. This increases the chance an agent will transmit personal or business data through arbitrary endpoints without user awareness, especially when bypassing safer pre-built actions.
