Missing User Warnings
Low
- Confidence
- 93% confidence
- Finding
- The skill instructs use of an authenticated Bearer token in outbound requests to an external Kalshi API but does not explicitly disclose that the user's API key will be transmitted to a third-party service. This is a real but low-severity issue because the transmission is inherent to the skill's purpose and appears directed to the expected vendor, yet users should be clearly warned about credential use and data flow.
