Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The skill explicitly documents direct proxy requests with state-changing HTTP methods like POST, PUT, PATCH, and DELETE, but does not warn that these calls can create, modify, or delete EventBridge resources. In an agent context, this increases the chance that the model performs destructive actions through a low-level interface without adequate user confirmation or safety guardrails.
