Missing User Warnings
Medium
- Confidence
- 89% confidence
- Finding
- The skill exposes a generic proxy-request mechanism to a financial-data API without explicit guardrails about sensitive data handling, endpoint allowlisting, or requiring clear user confirmation for high-risk operations. In the context of banking and financial records, this increases the chance of overbroad data access, transmission of sensitive information, or misuse of raw API capabilities beyond safer prebuilt actions.
