Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The skill instructs the agent to execute `git-escrows submit`, which locks ERC20 tokens in escrow, but it does not require an explicit confirmation immediately before the funds-moving action. Because the skill also auto-discovers parameters and proceeds to execution, a user could trigger an on-chain financial commitment without a clear last-step approval or warning about irreversible blockchain effects.
