Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The skill instructs users to generate a wallet private key and interact with an external, non-local service over plain HTTP, but it does not warn that private keys must never be exposed to the agent runtime, logs, shell history, or third-party services. In this context, combining credential generation with repeated unauthenticated network interactions materially increases the risk of wallet compromise, tracking, and misuse of the generated address or associated funds.
