Missing User Warnings
Medium
- Confidence
- 89% confidence
- Finding
- The skill explicitly documents a generic proxy-request capability that can send arbitrary HTTP methods to SAP Concur endpoints, but it does not warn that these calls may create, modify, or delete production travel/expense data. In an agent setting, this increases the chance of unintended state-changing operations because users may not realize that direct API calls are more dangerous than curated actions.
