Missing User Warnings
Medium
- Confidence
- 87% confidence
- Finding
- The skill documents a generic proxy request mechanism supporting POST, PUT, PATCH, and DELETE without an explicit warning to require user confirmation before data-changing operations. In an agent setting, that increases the risk of unintended or overly broad modifications to CRM/fundraising data, especially because direct API calls bypass safer, task-specific affordances.
