Missing User Warnings
Medium
- Confidence
- 91% confidence
- Finding
- The skill explicitly instructs use of raw private keys on the command line and local storage of an encrypted private key in ~/.sequence-builder/config.json, but does not warn that CLI arguments can leak via shell history, process listings, logs, or agent telemetry. In an AI-agent context, this is especially dangerous because secrets may be captured in transcripts or persisted automatically, enabling wallet compromise and theft of funds.
