Missing User Warnings
Medium
- Confidence
- 88% confidence
- Finding
- The skill documents a generic proxy mechanism that supports state-changing HTTP methods like POST, PUT, PATCH, and DELETE against a financial system API without requiring confirmation, scoping, or warning about destructive operations. In the context of ERP/financial data, this increases the risk that an agent could modify invoices, payments, journals, or other sensitive records based on an ambiguous prompt or incorrect action selection.
