Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The skill explicitly documents proxying arbitrary API requests and supports mutating HTTP methods like POST, PUT, PATCH, and DELETE without warning about side effects or requiring user confirmation. In a financial-services integration handling records, documents, tasks, and workflows, this can lead to unintended modification or deletion of remote data if the agent chooses raw requests over safer scoped actions.
