Missing User Warnings
Medium
- Confidence
- 91% confidence
- Finding
- The skill explicitly documents a generic proxy mechanism for arbitrary API requests to Plasmic, including support for state-changing HTTP methods like POST, PUT, PATCH, and DELETE, without requiring confirmation or warning about destructive operations. In an agent context, this expands capability from constrained prebuilt actions to effectively broad authenticated API access, increasing the risk of unintended modification, deletion, or exfiltration of remote data.
