Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The skill explicitly documents raw proxy requests with arbitrary paths and destructive HTTP methods such as POST, PUT, PATCH, and DELETE, but does not require explicit user confirmation or safety gating before use. In an HRIS context, this can enable modification or deletion of employee records, leave data, documents, or integrations through broad low-level API access.
