Tool Parameter Abuse
- Category
- Tool Misuse
- Confidence
- 91% confidence
- Finding
Payment deletion is particularly dangerous because it permanently removes revenue history and affects reporting, auditability, and user profiles. The skill text warns about this, but natural-language safeguards are weaker than enforcement, so an agent or wrapper that skips confirmations could still perform destructive actions with significant business impact.
- Content
md This skill is read-only by default, but the API also exposes **write** and **irreversible delete** operations and returns **personal data**. Before acting, observe these rules: - **Destructive operations require confirmation.** `DELETE /goals` and `DELETE /payments` permanently erase historical business data and cannot be undone. Never run them as a side effect of an analytics request. Always restate exactly what will be deleted (website, filters, date range, and how many records if known) and get explicit user confirmation first. Never run a DELETE without a date range or other narrowing filter unless the user has explicitly confirmed a full-history wipe. - **Treat a request to "clean up", "fix", or "remove" data as deletion, not querying**: confirm intent before translating it into a DELETE call. - **Visitor profiles and payments are PII.** Profiles can contain email, name, geolocation, full page history, and revenue. Only retrieve an individual visitor profile when the user explicitly asks about a specific person/visitor, and confirm they are authorized to view it. Present the minimum detail needed to answer; do not dump full identity, contact, and activity timelines unless asked. - **Minimize personal data on writes.** When recording payments/goals, send only the fields required for the task. Do not add `email`, `name`, or `customerId` unless the user explicitly provides them and they are needed for attribution.
