Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill explicitly states that payment authorization is handled automatically and requires use of an EVM private key, but it does not clearly warn the user that invoking the skill can spend funds from the connected wallet. In an agent context, this can lead to unintended on-chain charges or repeated paid requests without informed user consent, especially because the workflow is presented as frictionless and automatic.
