Missing User Warnings
Medium
- Confidence
- 88% confidence
- Finding
- The documentation explicitly instructs agents to use direct proxy requests with mutating methods such as POST, PUT, PATCH, and DELETE, but it does not require confirmation or warn that these calls may change or destroy business data. In an agent context, this increases the risk of unintended writes, destructive operations, or misuse of authenticated access through overly generic instructions.
