Missing User Warnings
Medium
- Confidence
- 89% confidence
- Finding
- This documentation describes endpoints that expose employee and account metadata, including names, phone numbers, usernames, login-related identifiers, and account access mappings, but it provides no privacy, authorization, or least-privilege guidance. In a skill meant to help ERP SSO integration, this can normalize broad querying of sensitive data and make misuse easier by integrators who may not implement adequate access controls or auditing.
