Missing User Warnings
Medium
- Confidence
- 90% confidence
- Finding
- The skill explicitly documents a generic proxy request capability supporting arbitrary HTTP methods, headers, body data, query params, and path params, but does not warn that this can perform state-changing or destructive operations. In an agent setting, this increases the chance that the model will issue unsafe POST/PUT/PATCH/DELETE requests without adequate confirmation, potentially modifying or deleting Mainstay data.
