Missing User Warnings
Medium
- Confidence
- 89% confidence
- Finding
- The skill explicitly documents arbitrary proxy requests to the Contis API, including support for POST, PUT, PATCH, and DELETE, without requiring user confirmation or warning that sensitive financial/account data may be transmitted or modified. In a payments context, this increases the risk of unintended disclosure, state-changing operations, or destructive requests being performed through an agent with network access.
