Missing User Warnings
Medium
- Confidence
- 91% confidence
- Finding
- The skill encourages querying wallet addresses, transaction history, holdings, and behavioral patterns through a remote third-party MCP server without warning users that these requests may disclose sensitive research targets, customer identifiers, or internal investigative activity to Zerion. In this context, blockchain addresses are public on-chain, but the act of aggregating, correlating, and sending analyst queries to an external service can still leak sensitive intent, customer relationships, and investigative focus.
