Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The README instructs users to place a wallet private key directly into configuration without a prominent warning that this credential grants control over funds and must be handled like a secret. In the context of a skill that performs automated x402 payments, this increases the chance of credential leakage through misconfiguration, accidental file exposure, backups, screenshots, or repository commits, which could lead to unauthorized fund transfers.
