Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill advertises an automatic payment flow that will pay on HTTP 402 and retry the request, but it does not clearly warn that this can spend real funds and transmit the original request to an external service. In an agent setting, auto-paying network requests is dangerous because prompts or tool chains may trigger unintended purchases, repeated charges, or disclosure of sensitive request data to third parties.
