Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The skill explicitly states that `kms.json` may contain private keys in plaintext when `BILLIONS_NETWORK_MASTER_KMS_KEY` is not set, but it does not place a strong, immediate warning before operational steps or require secure configuration first. Because this skill manages decentralized identity keys, plaintext key storage can directly enable identity theft, unauthorized signing, and persistent compromise if the local filesystem is exposed or backed up insecurely.
