Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The skill explicitly depends on a local .env containing PRIVATE_KEY and instructs the agent to check for that file before proceeding. Even though it does not literally print the key, directing an agent to access credential-bearing local files creates unnecessary exposure of secret material and normalizes handling of sensitive wallet credentials inside an automated workflow.
