Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The skill explicitly instructs the agent to issue direct proxy requests and documents support for mutating methods including POST, PUT, PATCH, and DELETE without requiring confirmation, safety checks, or warning about destructive effects. In an agent setting, this can enable unintended or overly broad modifications to external business data if the model interprets a request incorrectly or is prompt-injected into performing dangerous actions.
