Missing User Warnings
Medium
- Confidence
- 91% confidence
- Finding
- The skill explicitly instructs users to send USDC.k, $IP, and JAB to arbitrary 0x addresses but provides no warning that blockchain transfers are irreversible, error-prone, and vulnerable to misdirection or typos. In this context, the skill is not merely describing tokens abstractly; it is operationally guiding payment actions, which increases the likelihood of accidental fund loss or social-engineering-assisted transfers.
