Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The skill explicitly documents direct proxy requests with arbitrary HTTP methods, including destructive verbs like DELETE, but does not require confirmation, constrain endpoint scope, or warn about state-changing effects. In an agent setting, this increases the chance that the model performs unsafe write or delete operations against a live Veracode tenant based on ambiguous or malicious prompts.
