Missing User Warnings
Medium
- Confidence
- 88% confidence
- Finding
- The skill instructs users to supply a private key via CLI flag, environment variable, or config file without any warning about secret-handling risks. In this context, exposing a wallet private key can immediately compromise funds, and CLI flags in particular may leak through shell history, process listings, logs, or agent telemetry.
