Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The skill sends wallet addresses, portfolio lookups, NFT holdings, and transaction-history queries to Zapper's external GraphQL API, but the description does not clearly disclose this data flow. Users may reveal sensitive financial profiling data to a third party without informed consent, which creates privacy and compliance risk even if the API use is legitimate.
