Description-Behavior Mismatch
Medium
- Confidence
- 92% confidence
- Finding
- The CLI silently persists extracted patient insights to disk even though the skill is framed as a text-mining utility, which creates an unexpected data-retention path for potentially sensitive clinical information. In a healthcare-text context, writing derived patient data to a local JSON file by default can violate user expectations and increase the risk of accidental PHI exposure on shared systems, containers, or CI runners.
