Missing User Warnings
Medium
- Confidence
- 90% confidence
- Finding
- The skill enables ETH/token transfers and arbitrary transaction submission but does not explicitly instruct the agent to obtain clear user confirmation or warn that blockchain actions are irreversible. In an agent setting, this increases the risk of unintended asset movement, especially because the API key authorizes spending actions and the arbitrary transaction endpoint can invoke unknown contract behavior.
