Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The skill explicitly documents a generic proxy mechanism that supports POST, PUT, PATCH, and DELETE against the remote Rasa API, but it does not require user confirmation or warn that these operations may modify or delete production assistant data. In an agent setting, this increases the chance of unintended destructive actions because the model is encouraged to use direct API access when prebuilt actions are insufficient.
