Missing User Warnings
Medium
- Confidence
- 91% confidence
- Finding
- The skill explicitly instructs the agent to run external actions and raw proxy API requests without requiring user confirmation or warning that these operations may transmit data externally or modify remote state. In an agent setting, this can lead to unintended data disclosure, workflow execution, or state-changing API calls against a live Captain Data account.
