Missing User Warnings
Medium
- Confidence
- 90% confidence
- Finding
- The skill explicitly documents arbitrary proxy requests to the GreytHR API, including support for mutating HTTP methods and raw request bodies, but does not require confirmation, scope restrictions, or safety checks. In an HR/payroll context, this can expose or modify sensitive employee, attendance, leave, and payroll data, making unintended destructive or privacy-impacting actions more likely.
