Missing User Warnings
Medium
- Confidence
- 81% confidence
- Finding
- The skill explicitly enables action execution and raw proxy requests against HR/payroll systems, which can expose or modify highly sensitive employee data. Without built-in guidance to require explicit user confirmation, least-privilege handling, or sensitivity warnings before reads/writes, an agent could perform high-risk operations too casually.
