Tool Parameter Abuse
- Category
- Tool Misuse
- Confidence
- 89% confidence
- Finding
The skill exposes a destructive account-management operation, DELETE /api-keys/{id}, without any safety guidance, scoping restrictions, or confirmation requirements. In an agent context, parameter misuse or prompt injection could cause revocation of active credentials, leading to denial of service, operational lockout, or interruption of automated trading and fund-management workflows.
- Content
text GET /account → account info, plan, campaign usage POST /api-keys → generate additional API key DELETE /api-keys/{id} → revoke a key GET /pricing → credit pricing in SOL/USDC/P0 POST /credits/purchase → buy credits GET /credits/balance → check balance
