Missing User Warnings
Medium
- Confidence
- 89% confidence
- Finding
- The manifest explicitly requires a base58 Solana private key to be supplied to the skill for automated trading, but it provides no prominent warning about the sensitivity of that credential or the financial consequences of granting signing authority. In the context of an auto-trading skill, this increases the risk that users expose a hot-wallet key to code that can place trades or potentially misuse funds if the implementation is compromised or behaves unexpectedly.
