Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- This skill enables real-money network actions by spending USDC and sending request data to third-party endpoints, but it does not prominently require an explicit user-facing warning or confirmation immediately before payment execution. In an agent context, that omission increases the risk of unintended spending, privacy leakage, or ambiguous user consent, especially because the skill is user-invocable and designed to call arbitrary paid URLs.
