Missing User Warnings
Medium
- Confidence
- 91% confidence
- Finding
- The skill documents a generic proxy request capability that supports POST, PUT, PATCH, and DELETE against the Piggy API without emphasizing confirmation requirements, least-privilege usage, or the risk of modifying financial data. In a personal finance context, this can enable unintended account, budget, goal, or transaction changes if an agent uses raw requests instead of safer, constrained actions.
