Missing User Warnings
Medium
- Confidence
- 91% confidence
- Finding
- The documentation explicitly enables direct proxy requests with GET, POST, PUT, PATCH, and DELETE methods but does not require confirmation before mutating operations. In a CRM context, this can lead an agent to create, alter, or delete customer records through raw API calls without sufficient guardrails, increasing the chance of unintended data modification.
