Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The skill explicitly documents direct proxy requests supporting POST, PUT, PATCH, and DELETE without any guardrails about confirmation, least privilege, or destructive effects. In an agent setting, this lowers friction for arbitrary state-changing API calls and increases the chance of accidental or unauthorized modification or deletion of Nexudus data.
