Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The OpenAPI spec defines authenticated calls to a third-party service and supports sending account addresses and contract addresses, but the description shown to users does not clearly disclose that this data will be transmitted off-platform to Nodit. In an agent setting, users may provide wallet/account identifiers assuming local processing, so the lack of an explicit warning creates a meaningful privacy and data-sharing risk even though the endpoints are read-only.
