Missing User Warnings
Medium
- Confidence
- 88% confidence
- Finding
- The skill explicitly documents a generic proxy request capability supporting POST, PUT, PATCH, and DELETE against the connected Oracle Recruiting API without requiring guardrails, confirmation, or warnings about destructive changes. In an agent context, this increases the chance that a model could perform unintended writes or deletions to recruiting data, especially because the proxy can bypass safer prebuilt actions and operate directly on arbitrary endpoints.
