Missing User Warnings
Medium
- Confidence
- 91% confidence
- Finding
- The skill explicitly documents a generic proxy capability that can issue arbitrary HTTP methods, headers, query parameters, and bodies against the ForgeRock API, but it provides no warning or guardrails around destructive operations. In an identity and access management context, this can enable unintended modification or deletion of users, groups, attributes, or access settings if an agent uses the proxy naively or under prompt manipulation.
