Missing User Warnings
Medium
- Confidence
- 89% confidence
- Finding
- The skill explicitly documents raw proxy requests with arbitrary HTTP methods, including PUT, PATCH, and DELETE, but does not require confirmation or warn that these operations may modify or destroy remote MoonMail data. In an agent context, this increases the chance that the model performs high-impact state-changing actions directly against the API without adequate user intent verification.
