Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The skill explicitly documents a generic proxy mechanism that supports mutable HTTP methods like POST, PUT, PATCH, and DELETE without any warning, guardrails, or confirmation requirements. In a high-sensitivity HR platform like Ceipal, this can enable accidental or unauthorized modification of candidate, payroll, billing, or other business records if the agent uses raw requests instead of constrained actions.
