Missing User Warnings
Medium
- Confidence
- 91% confidence
- Finding
- The skill explicitly documents a generic proxy mechanism that supports arbitrary API paths and mutating methods including DELETE, POST, PUT, and PATCH, but does not require confirmation, scope validation, or a read-only-first workflow. In an agent context, this increases the risk of unintended destructive actions against Svix resources, especially when the model is following high-level user requests or ambiguous prompts.
