Missing User Warnings
Medium
- Confidence
- 91% confidence
- Finding
- The skill explicitly documents a destructive `Delete Invoice` action but provides no guidance to require user confirmation, verify intent, or apply safeguards before execution. In an agent setting, this increases the risk of accidental or overbroad destructive operations against financial records, especially if a model maps a user request imprecisely or acts on ambiguous instructions.
