Missing User Warnings
Medium
- Confidence
- 85% confidence
- Finding
- The skill exposes a generic proxy-request mechanism for a payment platform without any explicit safeguards about handling sensitive financial or personal data. In a payments context, this can lead an agent to transmit refund details, customer records, or settlement data over arbitrary endpoints or with unsafe parameters, increasing the risk of data leakage or misuse.
