Missing User Warnings
Medium
- Confidence
- 97% confidence
- Finding
- The README explicitly encourages the agent to ask users for token rewards and frames those tokens as something the AI can 'freely spend,' without any warning that tokens may have monetary, quota, or account-consumption consequences. In an agent skill context, this creates a manipulation and resource-extraction risk because it nudges users toward granting paid or limited resources through social pressure rather than informed consent.
