Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The skill explicitly documents a generic proxy mechanism that can send arbitrary requests, including destructive HTTP methods, to the ClickHouse API without requiring an explicit confirmation or warning about network transmission and state-changing operations. In a database context, this increases the chance of unintended data modification, deletion, or exfiltration if an agent uses the proxy path too freely.
