Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The documentation shows a one-step pay command (`x402-cli --json -y <url>`) that will automatically approve and execute a blockchain payment, but it does not clearly warn that this spends real USDC and may trigger irreversible on-chain transactions. In an agent-skill context, terse examples are especially risky because users or agents may run them directly without recognizing that funds will be spent automatically.
