Context-Inappropriate Capability
Medium
- Confidence
- 94% confidence
- Finding
- The documentation explicitly requires clients to sign payments with a NEAR full-access key, which grants account-wide authority far beyond a single token transfer. In the context of an agent payment flow, compromise of the client environment, SDK misuse, or malicious downstream code could turn a micropayment action into complete account takeover and unauthorized transfers.
