Missing User Warnings
Medium
- Confidence
- 90% confidence
- Finding
- The skill documents authenticated purchase, offer, review, and listing-management actions, including destructive and financial operations, without any explicit warning that they can spend money, alter marketplace state, or delete listings. In an agent setting, this increases the risk that an automation system invokes these endpoints without meaningful user confirmation or policy gating, leading to unauthorized transactions or destructive changes.
