Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The OpenAPI spec exposes live trading operations for creating and canceling orders without any explicit warning, confirmation requirement, or safety annotation that these actions affect a real exchange account. In an agent skill context, this increases the chance that a user or upstream agent invokes destructive financial actions unintentionally, especially because the same schema mixes harmless market-data endpoints with signed account/trading workflows.
