Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The skill explicitly documents a non-interactive API purchase flow that can charge the user's Vercel account using a locally stored bearer token, but it does not provide a prominent warning that this action incurs real financial cost. In an agent-skill context, providing a ready-to-run POST purchase example materially increases the risk of unintended or automated spending, especially compared with the CLI flow that at least mentions confirmation prompts.
