Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The skill explicitly documents proxying arbitrary API requests and includes mutating HTTP methods like POST, PUT, PATCH, and DELETE without any safety guidance, confirmation requirements, or read-only preference. In an agentic context, this increases the risk of unintended record creation, modification, or deletion if the model chooses direct API access for ambiguous user requests or hallucinated endpoints.
