Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The skill explicitly documents raw proxy access with GET, POST, PUT, PATCH, and DELETE against the HR Partner API, but does not require confirmation, read-only preference, or endpoint allowlisting. In an HR context, this can enable accidental or unauthorized modification of employee records, tickets, files, or announcements through broad natural-language prompts.
