Missing User Warnings
Medium
- Confidence
- 91% confidence
- Finding
- The API explicitly allows `/api/agent/send` with `execute: true`, which can immediately transfer funds without a separate confirmation call. Although the skill description says payments require explicit user confirmation by default, this reference does not strongly require the agent to obtain and record an out-of-band user confirmation immediately before using the direct-execute path, creating risk of unauthorized or accidental transfers.
