Missing User Warnings
Medium
- Confidence
- 91% confidence
- Finding
- The skill explicitly instructs the agent to use a generic authenticated proxy for arbitrary API paths and supports all major HTTP methods, including potentially destructive ones like DELETE, PATCH, and POST, without requiring confirmation or warning about sensitive data transmission. In the context of a network-enabled integration skill, this meaningfully increases the chance of unsafe requests, data leakage, or unintended state-changing operations against the user's Conversionomics account.
