Missing User Warnings
Medium
- Confidence
- 90% confidence
- Finding
- The manifest declares a required environment variable `ORACLAW_API_KEY`, which indicates the skill depends on an external service, but the skill content does not clearly warn users that credentials will be used or that simulation inputs may be sent off-platform. This creates a real security and privacy risk because agents or users may invoke the skill without understanding the trust boundary, potentially exposing sensitive business, finance, or trading data to a third-party service.
