Missing User Warnings
Medium
- Confidence
- 91% confidence
- Finding
- The skill explicitly documents running arbitrary actions and direct proxy requests against the MATTR API without warning that these operations may create, update, or delete tenant resources. In an agent setting, this increases the chance of unintended state-changing or irreversible operations being performed without adequate user confirmation or risk framing.
