The descriptor may be contained in the warrant. This provides a convenient mechanism for ``quick and dirty'' services. There are some limitations to this mechanism of which the client must be aware:
The descriptor and any data it contains are available to the node before it can be determined whether the node is trustworthy. The method should not be used for any purpose requiring real security.
The base API only allows embedded descriptors to be used to create services in the same accounting group as the client. If the warrant indicates the new netlet is to have a newly created accounting group then the descriptor will be rejected.