Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill instructs the agent to make an x402-authenticated request using a live EVM private key, and the x402 client will automatically authorize payment, but the usage section does not present a prominent warning at the point of invocation that each call will spend wallet funds. In an agent setting, this can lead to unintended paid requests, hidden recurring cost, and wallet fund depletion if the skill is invoked automatically or repeatedly.
