Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The skill explicitly documents a generic authenticated proxy that supports POST, PUT, PATCH, and DELETE without any guardrails, warnings, or confirmation requirements for state-changing requests. In an agent setting, this increases the risk of accidental or prompt-induced destructive actions against the Assembled tenant, especially when the model falls back to raw requests instead of curated actions.
