Missing User Warnings
Medium
- Confidence
- 84% confidence
- Finding
- The skill explicitly documents a generic request primitive supporting POST, PUT, PATCH, and DELETE without requiring confirmation or warning about state-changing and irreversible operations. In an agent context, this increases the risk of unintended destructive API calls against Ngrok resources such as tunnels, reserved domains, or endpoint configurations.
