Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill explicitly requires an EVM private key and states that the client will automatically handle payment authorization, but it does not present a prominent warning about the financial and wallet-security implications. This is dangerous because users or agents may invoke the skill without realizing it can spend funds on their behalf and requires highly sensitive key material in the environment.
