Missing User Warnings
Medium
- Confidence
- 89% confidence
- Finding
- The skill explicitly documents raw proxy access with mutating HTTP methods like POST, PUT, PATCH, and DELETE, but does not instruct the agent to obtain explicit confirmation before performing state-changing operations. In an agent setting, this increases the chance of unintended writes, deletions, or workflow changes in a live HR system containing sensitive recruiting data.
