Missing User Warnings
Medium
- Confidence
- 81% confidence
- Finding
- The proxy request section instructs the agent to send direct API requests through Membrane but does not warn that arbitrary paths, headers, query parameters, and bodies may transmit sensitive user or enterprise data to an external service. In a skill that manages records and workflows, this omission increases the risk of unintended data disclosure or destructive API calls if an agent acts without explicit user awareness or confirmation.
