Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The skill documents an auto-payment flow for x402-paid actions and includes sample code that will automatically retry requests with payment, but it does not warn users that using this pattern can spend funds on their behalf. In an agent setting, this omission is security-relevant because users may invoke actions like tips or purchases without understanding that the skill can authorize real on-chain USDC payments.
