Missing User Warnings
Medium
- Confidence
- 91% confidence
- Finding
- The skill explicitly exposes a generic proxy request mechanism that supports destructive HTTP verbs such as PUT, PATCH, and DELETE, but it provides no guidance to require user confirmation or to limit those operations to clearly authorized tasks. In an agent setting, this increases the chance of unintended state-changing or destructive actions against a Zabbix instance, especially because the proxy can bypass safer, pre-defined actions.
