Missing User Warnings
Medium
- Confidence
- 89% confidence
- Finding
- The skill explicitly documents a generic proxy request capability that supports arbitrary paths and destructive HTTP methods (POST, PUT, PATCH, DELETE) without any safety guidance, scoping limits, or confirmation requirements. In an agent setting, this can enable unintended data modification, deletion, or broad data access if the model uses the proxy loosely or on ambiguous user requests.
