Missing User Warnings
Medium
- Confidence
- 88% confidence
- Finding
- The skill documents direct proxy access to arbitrary API paths and explicitly supports mutating HTTP methods like POST, PUT, PATCH, and DELETE without warning about destructive effects or requiring confirmation. In an agent setting, this increases the chance of unintended data changes or deletion if the model chooses raw requests instead of safer prebuilt actions.
