Missing User Warnings
Medium
- Confidence
- 88% confidence
- Finding
- The README explicitly documents sending detailed transaction context, including tool metadata, session identifiers, and raw parameters, to an external backend, but it does not clearly warn operators about the sensitivity of this data or advise on minimization. In a blockchain agent setting, these fields can expose wallet destinations, transaction intent, internal session correlation data, and potentially secrets or sensitive operational context if raw parameters are forwarded verbatim.
