Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The skill explicitly instructs the agent to call third-party marketplace services where payment is automatically deducted from the user's USDC balance, but it does not require explicit user confirmation before incurring charges. In an agent setting, this can lead to unintended spending, especially if the agent autonomously discovers and invokes paid services based on user requests.
