Missing User Warnings
Medium
- Confidence
- 89% confidence
- Finding
- The capability description includes governed write actions that can disable or enable users, revoke sessions, replace redirect URIs, and rotate client secrets, but it does not explicitly warn the operator about their immediate security and availability effects. In an identity-provider skill, these actions can lock out legitimate users, restore access for previously disabled accounts, disrupt SSO, or weaken OAuth client boundaries if invoked without clear user-facing caution and confirmation semantics.
