Missing User Warnings
Medium
- Confidence
- 91% confidence
- Finding
- The skill explicitly documents direct proxy requests with support for POST, PUT, PATCH, and DELETE, but does not require confirmation, warn about destructive effects, or encourage least-privilege patterns before mutation. In an agent setting, this increases the risk that a user request is translated into a state-changing API call that modifies or deletes Amity data without sufficient user awareness or validation.
