Missing User Warnings
Medium
- Confidence
- 88% confidence
- Finding
- The skill enables real-money custodial trading and explicitly notes that v1 has no per-user limit UI, yet it does not prominently warn about financial loss, liquidation, leverage risk, or the practical consequence that users may rely only on server-side caps. In a trading automation context, omission of these disclosures can cause users to authorize risky actions without understanding loss boundaries, making this a meaningful safety and security weakness even if it is not an exploit in the traditional software sense.
