Missing User Warnings
Medium
- Confidence
- 98% confidence
- Finding
- The skill exposes a purchase endpoint for card packs with explicit dollar prices and encourages autonomous use, but it provides no warning, confirmation requirement, spending limit, or user-consent safeguard before initiating charges. In an autonomous agent context, this can lead to unintended real-money spending or repeated purchases triggered by optimization logic, making the omission a genuine security and safety issue.
