Missing User Warnings
Medium
- Confidence
- 87% confidence
- Finding
- The skill explicitly documents a generic proxy request mechanism supporting arbitrary paths and destructive HTTP methods without requiring confirmation, least-privilege guidance, or warnings about sending sensitive document data to external endpoints. In a document automation context, this increases the risk of unauthorized data transmission, template modification, or deletion if an agent uses raw requests instead of constrained actions.
