Missing User Warnings
Medium
- Confidence
- 89% confidence
- Finding
- The skill explicitly describes performing create, update, and delete operations against the real API, including destructive deletion, without any warning, confirmation, scope restriction, or safety guardrails. Even if intended as an integration test, documenting and enabling destructive actions on a live endpoint increases the risk of accidental or unauthorized deletion if the skill is invoked in the wrong environment or with an unexpected slug.
