Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The skill explicitly facilitates access to customers' financial data and also supports raw proxy requests, but it does not instruct the agent to obtain explicit user authorization, minimize retrieved data, or confirm before accessing or transmitting sensitive records. In a financial-data context, this omission can enable over-collection or unintended disclosure of bank/account information even when the underlying API access is legitimate.
