Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The skill explicitly documents raw proxy requests to the external API without requiring confirmation, read-only defaults, or warning that these requests may modify or transmit sensitive data. Because proxy requests can perform arbitrary authenticated operations, an agent could execute destructive or privacy-impacting actions more easily than when constrained to vetted high-level actions.
