Missing User Warnings
Medium
- Confidence
- 91% confidence
- Finding
- The skill explicitly documents a generic proxy mechanism that supports destructive HTTP methods like POST, PUT, PATCH, and DELETE without any warning, confirmation requirement, or guardrails around data-changing operations. In an agent setting, this can enable unintended or overly broad writes directly against the Signaturit API, increasing the risk of accidental modification, deletion, or misuse of sensitive signing workflows and records.
