Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The manifest requires a SIMMER_API_KEY for an external trading service but provides no visible warning in the manifest about credential use, transmission to third-party infrastructure, or the operational risks of connecting a live trading agent. In a finance/trading skill, silent credential requirements are more sensitive because users may expose funded accounts or authorize real market actions without clear notice.
