Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The manifest requires a sensitive API key for a trading skill but does not disclose credential use, trading authority, or risk to the user in the manifest metadata. In a financial trading context, this is more dangerous because users may grant credentials without understanding that the skill can place trades or access account capabilities, increasing the risk of unauthorized or misunderstood financial actions.
