Missing User Warnings
Medium
- Confidence
- 89% confidence
- Finding
- The README describes sending payment deeplinks via chat platforms and verifying transactions on-chain, but it does not clearly warn users that wallet addresses, payment metadata, and transaction details may be exposed to third-party messaging providers and RPC endpoints. In a payment-related skill, this omission can lead users to underestimate privacy, tracking, and metadata leakage risks, especially when conversations occur over Telegram, Discord, or similar services.
