Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The skill instructs users to place a private key directly into an environment variable, which increases the chance of secret exposure through shell history, process inspection, logs, crash reports, or inherited child processes. Because this skill is specifically designed to sign blockchain payments, compromise of the key would allow unauthorized spending of wallet funds and misuse of the identity associated with that wallet.
