Missing User Warnings
Medium
- Confidence
- 90% confidence
- Finding
- The skill directs agents to send wallet identifiers, loan metadata, repayment request IDs, and transaction hashes to a third-party API, but does not clearly disclose this data-sharing or its trust implications. In an agentic context, this can cause autonomous systems to exfiltrate operational financial metadata to an external service without informed consent or policy checks.
