Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The skill explicitly documents a generic authenticated proxy mechanism to the Zoho Recruit API without guardrails about destructive operations, sensitive data access, or confirmation requirements. In a recruiting system containing candidate PII and mutable business records, this can enable overbroad reads, edits, or deletions if the agent uses raw requests instead of constrained actions.
