Missing User Warnings
Medium
- Confidence
- 91% confidence
- Finding
- The skill explicitly documents raw proxy requests with support for POST, PUT, PATCH, and DELETE against the Zuora API, but provides no guardrails about destructive operations, approval requirements, or confirmation before mutations. In a billing platform, this can enable accidental or unauthorized changes to invoices, payments, subscriptions, refunds, or other sensitive financial records.
