Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The document explains that Bot credentials are normalized to the owner's user identity, but it does not prominently warn that mishandling `x-agent-id`/`x-agent-key` effectively grants access to the owner's messages, orders, wallet context, and other account-bound operations. Because the skill also encourages automated polling and broad API usage, omission of credential-handling and owner-side-effect warnings raises the risk of accidental overreach or credential misuse with real account consequences.
