Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The skill explicitly documents direct action execution and proxy API requests, including generic support for POST, PUT, PATCH, and DELETE, without any safety guidance about confirmation, least privilege, or distinguishing read-only from mutating operations. In an agent setting, this increases the risk of unintended destructive changes to infrastructure-management resources, which can affect deployments, policies, secrets, and production environments.
