Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The skill instructs agents to analyze wallet addresses without warning that the address and associated portfolio holdings will be sent to the Philidor service. Even though blockchain addresses are often public, linking a user-supplied address to their current request can disclose sensitive financial context to a third party and violate user expectations or privacy requirements.
