Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The skill instructs users to configure exchange API credentials and use commands that query balances and orders, but it does not clearly warn that these actions send authenticated account data requests to third-party exchanges and may expose sensitive financial metadata. In a portfolio-management context, this omission can mislead users into treating the skill as local-only or low-risk, increasing the chance of unintended disclosure or unsafe credential use.
