Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The skill exposes a generic proxy request mechanism that supports destructive HTTP methods like POST, PUT, PATCH, and DELETE, but it does not require confirmation or warn that these operations may modify or delete TTN resources. In an agent setting, this increases the chance of unintended state-changing requests against real IoT infrastructure, especially if the agent falls back to raw API usage when prebuilt actions are unavailable.
