Missing User Warnings
Medium
- Confidence
- 80% confidence
- Finding
- The script reads a raw hex private key directly from a plaintext file and then uses it to authorize blockchain payment. In an agent skill context, this is dangerous because it encourages insecure secret handling, increases the chance of key exposure via filesystem leakage, logs, backups, or misconfigured permissions, and grants direct spending authority if the key is compromised.
