Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The skill explicitly enables arbitrary proxy requests to the Snapchat Marketing API, including state-changing HTTP methods like POST, PUT, PATCH, and DELETE, but does not require confirmation or warn about destructive effects. In an agent setting, this increases the risk that a vague, mistaken, or manipulated instruction could cause unauthorized campaign changes, data corruption, or deletions through a flexible low-level interface.
