Missing User Warnings
Medium
- Confidence
- 91% confidence
- Finding
- The skill explicitly documents a generic proxy request capability that can send arbitrary HTTP methods, headers, query parameters, and bodies to the connected Microcks API, including destructive methods like DELETE, POST, PUT, and PATCH. Without an explicit user-facing warning or confirmation requirement, an agent could transmit sensitive data or perform state-changing operations on behalf of the user without adequate awareness or consent.
