Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill instructs the agent to make an authenticated paid request using an EVM private key and states that payment authorization is handled automatically, but it does not clearly warn that invoking the skill can spend on-chain funds or involve transmission/use of wallet-derived credentials. In an agent context, this creates a real risk of unintended financial charges and unsafe secret use because users may treat the call as a normal read-only API request.
