Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill describes creating escrow contracts, registering profiles, and releasing payments through an external service handling real on-chain funds, but it does not prominently warn users that these actions transmit data to a third party and can trigger irreversible financial consequences. In an agent setting, lack of explicit consent and risk disclosure can cause unintended profile publication, wallet/address disclosure, or movement/release of escrowed funds based on automated workflow execution.
