Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The skill describes paid endpoints and says an x402-compatible client will pay automatically, but it does not present a prominent upfront warning that invoking requests can trigger real on-chain USDC payments from the user's wallet. In an agent setting, this omission can cause unintended spending because users may treat the skill like a normal read-only API integration rather than a transaction-capable action.
