Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The skill explicitly documents raw proxy access to the 1Password API, including state-changing methods like POST, PUT, PATCH, and DELETE, without requiring confirmation safeguards or warning about sensitive secret exposure. In the context of a password manager, this increases the chance an agent could modify, delete, or exfiltrate vault contents through overly broad or under-reviewed requests.
