Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The walkthrough explicitly demonstrates passing a raw private key on the command line via `--import 0xYOUR_PRIVATE_KEY` without any adjacent warning about shell history, process list exposure, CI log leakage, or safer alternatives. In a wallet-funding/on-chain-payment skill, this is especially dangerous because compromise of the imported key can directly lead to irreversible loss of funds and unauthorized signing.
