Missing User Warnings
Medium
- Confidence
- 90% confidence
- Finding
- The skill explicitly documents direct proxy requests and supports destructive HTTP methods such as POST, PUT, PATCH, and DELETE without requiring confirmation or warning about data modification risk. In an agent setting, this increases the chance of unintended record changes or deletion, especially if the model follows high-level user requests ambiguously or uses raw requests when safer predefined actions exist.
