Missing User Warnings
Medium
- Confidence
- 84% confidence
- Finding
- The skill explicitly documents raw proxy requests to the Discord API, including support for POST, PUT, PATCH, and DELETE, without any warning about destructive operations, permission boundaries, or the need for user confirmation before modifying data. In an agent context, this increases the risk of unintended message deletion, channel changes, membership changes, or other state-altering actions being performed too readily.
