Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The skill instructs the agent to make an x402-authenticated request where payment authorization is handled automatically, but it does not warn that executing the call can spend real funds from the user's wallet. In an agent setting, this is dangerous because a seemingly routine data-fetch action can trigger unintended paid transactions, especially if the user has not explicitly consented to spending.
