Missing User Warnings
High
- Confidence
- 94% confidence
- Finding
- The code performs outbound payment actions immediately via both invoice payment and Lightning address payment without any confirmation, policy check, recipient verification, or spending limit. In an agent or automation context, this is dangerous because any invocation path that reaches this code can trigger irreversible fund transfers from the connected wallet.
