Missing User Warnings
Medium
- Confidence
- 87% confidence
- Finding
- The skill explicitly documents a generic proxy request mechanism supporting POST, PUT, PATCH, and DELETE without any corresponding warning or guardrail about destructive operations. In an agent setting, this increases the chance that the model may issue raw state-changing API calls against Simvoly resources, potentially modifying or deleting websites, stores, forms, or membership data without clear user intent verification.
