Missing User Warnings
Medium
- Confidence
- 84% confidence
- Finding
- The skill explicitly encourages direct proxy requests to the external API without requiring confirmation, allowlisting, or warning about the risks of raw endpoint access. In an agent setting, this can bypass safer pre-built actions and increase the chance of unintended state-changing requests, overbroad data access, or misuse of authenticated capabilities against the connected Scraptio account.
