Missing User Warnings
Medium
- Confidence
- 91% confidence
- Finding
- The skill explicitly instructs the agent to run actions and send direct proxy requests to the Supabase API without requiring confirmation gates for state-changing operations or warning that these calls may modify, delete, or exfiltrate data. In an agent setting, this increases the risk of unintended writes, destructive actions, or transmission of sensitive database contents based on ambiguous prompts.
