Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The skill documents a generic proxy mechanism that supports arbitrary paths and destructive HTTP methods like POST, PUT, PATCH, and DELETE without instructing the agent to obtain confirmation before state-changing operations. In a contract-management platform, this can lead to unintended modification or deletion of legal records, agreements, or configuration through overly permissive agent behavior.
