Missing User Warnings
Medium
- Confidence
- 90% confidence
- Finding
- The skill explicitly documents a generic proxy mechanism that supports POST, PUT, PATCH, and DELETE against the Razorpay API without any guardrails, confirmation requirements, or warning that these methods can create, modify, or delete live payment-platform data. In a payments context, exposing raw mutating requests increases the risk of accidental destructive actions or unsafe agent-generated calls, especially when the proxy is presented as a fallback for unsupported use cases.
