Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The skill explicitly documents raw proxy requests with support for POST, PUT, PATCH, and DELETE, but does not warn that these can modify or delete billing, mandate, subscription, or payment data. In a payments context, encouraging direct state-changing API access without guardrails increases the chance of accidental destructive actions or unsafe agent behavior.
