Missing User Warnings
Medium
- Confidence
- 90% confidence
- Finding
- The manifest requires a live API key and declares an automated trading entrypoint, but it provides no user-facing disclosure about credential handling, autonomous order placement, or financial risk. In a trading skill, this omission is security-relevant because users may supply sensitive credentials and enable execution without understanding that the agent can place real trades and incur losses.
