Don’t ever paste or share with anyone your $modx->siteId or HTTP_MODAUTH key. It keeps your site secure.
No. All HTTP_MODAUTH does is prevent middleman attacks - someone hijacking your user session to run processors via connectors.
That was clear from the session cookie - the question is -> can the user with limited rights inject request to the things he has no permission?