Missing User Warnings
Medium
- Confidence
- 91% confidence
- Finding
- The skill explicitly instructs the agent to use a generic proxy capable of GET, POST, PUT, PATCH, and DELETE against the AgencyZoom API, but it does not require confirmation, scoping, or safety checks before state-changing operations. In a CRM context, this can lead an agent to modify or delete customer, lead, note, task, or policy data based on ambiguous prompts or incorrect assumptions, increasing the risk of unintended destructive actions.
