Missing User Warnings
Medium
- Confidence
- 96% confidence
- Finding
- The skill gives step-by-step instructions for initiating paid blockchain marketplace actions, including x402 payment retries and listing fees, but does not clearly warn that these payments may be real, irreversible, and subject to chain-specific fees or loss from incorrect transactions. In an agent setting, this increases the chance that a user or automation triggers a purchase or listing payment without informed consent, especially because the skill is marked user-invocable and presents the payment flow as routine API usage.
