Missing User Warnings
Medium
- Confidence
- 88% confidence
- Finding
- The skill explicitly states it performs real publish, update, and delete operations against a live API, but it does not include a clear warning about side effects, required authorization boundaries, or the fact that persistent external state will be modified. In an agent setting, this increases the chance of unintended destructive actions or use in the wrong environment, especially because deletion is part of the normal workflow.
