Missing User Warnings
Medium
- Confidence
- 87% confidence
- Finding
- The skill exposes a generic authenticated proxy request mechanism that can issue arbitrary HTTP methods against the SignWell API, including potentially destructive endpoints, without embedding guardrails or confirmation requirements. In an agent setting, this expands capability beyond curated actions and increases the risk of unintended modification, deletion, or bulk operations if the agent misinterprets a prompt or is manipulated.
