Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The skill explicitly enables direct proxy requests to the AWS Well-Architected API, including destructive HTTP verbs like PUT, PATCH, and DELETE, but provides no warning or confirmation guidance before such calls. In an agent context, this increases the chance of unintended state-changing operations against cloud architecture records, especially if the model falls back to raw requests when actions are unavailable.
