Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The skill explicitly instructs the agent to send direct proxy requests, including support for POST, PUT, PATCH, and DELETE, without any warning about sensitive data transmission, destructive effects, or confirmation requirements. In an agentic context, this can lead to unintended modification, deletion, or exfiltration of HypeAuditor data if the agent interprets a user request too broadly or uses the proxy as a fallback without safeguards.
