Missing User Warnings
Medium
- Confidence
- 84% confidence
- Finding
- The skill explicitly instructs the agent to send direct proxy requests to the Insomnia API, including support for arbitrary methods, headers, query parameters, and request bodies, without requiring user confirmation or warning about data transmission and state-changing effects. In an agent setting, this increases the risk of silent external data disclosure or unintended modifications to remote resources if the model chooses a raw request path too aggressively.
