Missing User Warnings
Medium
- Confidence
- 91% confidence
- Finding
- The skill explicitly instructs the agent to use a generic proxy capable of issuing GET, POST, PUT, PATCH, and DELETE requests to the Directus API, but it provides no guardrails about confirming destructive operations, scoping access, or warning about data loss. In a skill whose purpose is to manage collections, users, flows, and content, this materially increases the chance that an agent can modify or delete production data through broad direct API access.
