Missing User Warnings
Medium
- Confidence
- 97% confidence
- Finding
- The skill instructs the agent to make an x402-authenticated request using an EVM private key and states that payment authorization happens automatically, but it does not present a prominent user-facing warning that using the skill can spend wallet funds. Because the skill is tied to a blockchain wallet and per-call charges, a user or calling agent may invoke it without understanding that real monetary authorization and on-chain payment behavior are involved.
