Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill instructs users to perform a real posting flow using a PRIVATE_KEY environment variable or --private-key flag without clearly warning that this authorizes irreversible onchain spending and exposes highly sensitive credentials to the local shell, process list, logs, or agent tooling. In an agent context, this is especially dangerous because an autonomous system may follow the example directly and spend funds or mishandle the private key without explicit user confirmation.
