Missing User Warnings
Medium
- Confidence
- 88% confidence
- Finding
- The skill explicitly documents raw proxy requests with support for destructive HTTP methods like POST, PUT, PATCH, and DELETE, but provides no guardrails about confirmation, scoping, or dry-run/read-only preference. In an agent setting, this increases the risk of unintended modification or deletion of CMS data because the agent is empowered to act directly against the API with authenticated access.
