Missing User Warnings
Medium
- Confidence
- 96% confidence
- Finding
- The skill explicitly asks the user to provide extremely sensitive material, including a wallet mnemonic and service credentials, but does not warn against sharing them with the agent or recommend safer handling paths. In this context, the mnemonic controls funds and the API credentials can provision infrastructure, so collecting them through an agent materially increases the risk of credential exposure, logging leakage, or misuse.
