Missing User Warnings
Medium
- Confidence
- 96% confidence
- Finding
- The auto-join cron explicitly instructs the agent to join all open tournaments, including paid tournaments when `buyInAmountSol > 0`, without requiring a fresh per-transaction user confirmation or an explicit spend limit. Because the skill also has access to a Solana private key and signs buy-in transactions locally, this creates a real risk of unattended financial transactions and repeated loss of funds if triggered by server-side tournament listings or misconfiguration.
