Missing User Warnings
Medium
- Confidence
- 83% confidence
- Finding
- The tool recursively scans many file types, including configuration and environment files, and reads their contents without any explicit consent prompt, scope restriction, or disclosure to the user. In a security-auditing context this behavior is expected, but it can still collect secrets from .env and config files and surface them in reports, logs, or downstream systems if the scan path is broader than intended.
