Missing User Warnings
Medium
- Confidence
- 88% confidence
- Finding
- The manifest declares a required API credential (`SIMMER_API_KEY`) but gives the user no explanation of what the key is used for, where it is sent, or what actions it authorizes. In an automated trading skill, undisclosed credential use increases the risk of users supplying sensitive secrets without understanding scope, and it impairs informed consent and security review.
