Missing User Warnings
Medium
- Confidence
- 90% confidence
- Finding
- The skill instructs users to perform direct REST API operations with curl against a remote service without clearly warning that these actions may modify live data, transmit credentials, or affect production entities. In an agent skill context, this increases the chance of unsafe use, accidental state changes, and inappropriate handling of secrets, especially since the notes imply privileged API access.
