Missing User Warnings
Medium
- Confidence
- 98% confidence
- Finding
- The skill explicitly instructs the user to hand an API key to the agent so it can perform wallet creation, funding, token launch, and trading actions on the user's behalf. That credential appears to grant broad transactional capability, so exposing it to an LLM agent or any intermediary can enable unauthorized launches, trades, wallet operations, or key misuse if the conversation, logs, or integrations are compromised.
