Missing User Warnings
Medium
- Confidence
- 87% confidence
- Finding
- The skill documents a generic proxy mechanism supporting arbitrary HTTP methods, headers, body data, and path parameters without guardrails or confirmation requirements for destructive operations. In an agent context, this can enable unintended or unsafe API calls against connected services, especially if the model uses the proxy when a safer prebuilt action is unavailable.
