Missing User Warnings
Medium
- Confidence
- 83% confidence
- Finding
- The skill explicitly documents direct proxy requests with destructive HTTP methods like POST, PUT, PATCH, and DELETE, but does not pair that capability with clear guidance to obtain user confirmation before changing or deleting data. In an agent setting, this increases the risk of unintended state-changing operations against production CRM records, especially when raw endpoint access bypasses the safer affordances of predefined actions.
