Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The skill explicitly instructs agents to persist the wallet encryption password in ~/.nansen/.env and source it before executing trades, but provides no guidance on file permissions, secret handling, or safer alternatives. Because this skill performs irreversible on-chain transactions, compromise of that password can enable wallet access and unauthorized trades, making the omission materially dangerous in context.
