Missing User Warnings
Medium
- Confidence
- 84% confidence
- Finding
- The skill explicitly documents raw proxy requests and supports state-changing methods like POST, PUT, PATCH, and DELETE without any safety guidance, confirmation requirement, or distinction between read-only and mutating operations. In an agent setting, this increases the chance of unintended record modification or deletion, especially when the model falls back from prebuilt actions to direct API calls.
