Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The skill instructs the agent to use an environment-stored EVM private key to authenticate paid requests, but it provides no warning about the sensitivity of that credential, the financial authority it confers, or safe handling expectations. In this context, the key can authorize on-chain payment flows, so normalizing direct use of a wallet private key in a third-party request pattern increases the risk of accidental exposure, misuse, or unsafe agent integrations.
