Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The README instructs users to send a bearer token to an external API but does not clearly disclose that credentials and trading-related context leave the local agent environment. In an agent-skill context, this is security-relevant because users may treat the skill as local logic while it actually causes authenticated outbound transmission to a third-party service.
