Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The skill exposes purchasing functionality using USDC on Base or Solana and references an external commerce API, but the description does not clearly warn users that invoking the purchase flow can trigger real cryptocurrency payments to a third-party service. In an agent setting, insufficient disclosure increases the risk of unintended financial transactions, especially if users or downstream agents treat the skill like a normal content browser rather than a payment-capable commerce integration.
