Missing User Warnings
Medium
- Confidence
- 78% confidence
- Finding
- The schema exposes an endpoint that retrieves wallet address holdings/positions but does not warn that this can reveal sensitive financial profiling information about a user or third party. In an agent skill context, absence of disclosure and consent guidance increases the risk of privacy-invasive use, especially because wallet addresses can be tied to transaction history and investment behavior.
