Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The manifest declares a required API credential (`SIMMER_API_KEY`) but does not provide any user-facing disclosure about external service usage, credential access, or what the key will be used for. In an automated trading skill, this matters because the skill can interact with third-party infrastructure and place trades, so users should be explicitly warned before supplying sensitive credentials.
