Tool Parameter Abuse
- Category
- Tool Misuse
- Confidence
- 97% confidence
- Finding
The documentation exposes a destructive parameterized deletion path for broker portfolio snapshots on live accounts (
sandbox=false), creating a real risk of tool misuse if an agent populates parameters incorrectly or is prompt-influenced into targeting production data. Because these are authenticated external API actions, a parameter mix-up can cause irreversible account-state changes.- Content
md - `sandbox=false` for live connection, `sandbox=true` for sandbox - Removes the connection and its saved API key; portfolio snapshot **history is preserved** - To also delete snapshot history, first use `DELETE /portfolio/broker/{broker}?sandbox=false` - **ALWAYS confirm before disconnecting** — reconnection requires the mobile app **Difference between the two delete endpoints:**
