Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The skill exposes a generic authenticated proxy request capability, including support for POST, PUT, PATCH, and DELETE, without warning the agent or user that arbitrary API calls may modify or delete production SimplyBook.me data. In an agent setting, this increases the chance of unintended destructive actions or overbroad requests being issued through a valid authenticated connection.
