Missing User Warnings
Medium
- Confidence
- 89% confidence
- Finding
- The skill instructs users to place raw EVM and Solana private keys in environment variables and then demonstrates code that automatically signs and submits payments to remote resources. In the context of an agent skill, this is dangerous because it normalizes direct secret injection and autonomous fund spending without explicit safety guardrails, spending limits, key isolation, or user confirmation.
