Missing User Warnings
Medium
- Confidence
- 89% confidence
- Finding
- The manifest explicitly requires an API credential and configures a managed trading entrypoint, but it does not present any visible user-facing warning that the skill can place automated trades using that credential. In a trading skill, this omission is security-relevant because users may supply live credentials without understanding financial risk, automated execution scope, or the consequences of autostart/managed operation.
