Missing User Warnings
Medium
- Confidence
- 89% confidence
- Finding
- The skill explicitly encourages direct proxy requests to the IDnow API without guardrails about sensitive identity data, destructive endpoints, or the need for user confirmation on write operations. In an identity-verification context, raw API access increases the chance an agent will retrieve PII, alter settings, or perform irreversible administrative actions without adequate validation.
