Missing User Warnings
Medium
- Confidence
- 89% confidence
- Finding
- The manifest requires a live API credential and clearly configures an automated trading entrypoint, but it provides no user-facing disclosure about outbound network access, credential use, or the fact that the skill can place trades. In a trading skill, this omission is security-relevant because users may supply sensitive credentials without understanding the external actions the agent can perform on their behalf.
