Missing User Warnings
Medium
- Confidence
- 88% confidence
- Finding
- The skill explicitly documents arbitrary proxied API requests, including POST, PUT, PATCH, and DELETE, without guardrails around sensitive data transmission or destructive operations. In an agent setting, this can normalize direct state-changing requests and increase the chance of unintended modification, deletion, or overbroad data access if the agent follows user prompts without additional confirmation.
