Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The skill explicitly documents raw proxy requests to the Verimi API and notes that authentication headers are injected automatically, but it does not warn that these requests may read, modify, or transmit sensitive identity data or trigger destructive API operations. In a high-sensitivity identity/KYC context, this omission can lead an agent to perform unsafe direct calls without sufficient user confirmation or endpoint validation.
