Missing User Warnings
Medium
- Confidence
- 81% confidence
- Finding
- The skill explicitly documents direct proxying of arbitrary requests to the Saleshood API without pairing that capability with safeguards like confirmation for write operations, endpoint allowlisting, or warnings about sensitive data access and modification. In an agentic setting, this increases the chance of overbroad reads, unintended writes, or misuse of authenticated access through generic request construction.
