Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The skill explicitly instructs the agent to use generic proxy requests, including POST, PUT, PATCH, and DELETE, without requiring confirmation or emphasizing that these methods can modify or delete user data. In an agent setting, this increases the risk of unintended destructive actions if a model interprets a vague user request too aggressively or uses the proxy as a fallback without adequate safeguards.
