Context-Inappropriate Capability
Medium
- Confidence
- 92% confidence
- Finding
- This code sends prompts to Google's Gemini API and, elsewhere in the module, those prompts can include conversation history and real account context. Even if networked AI is part of the feature, the implementation lacks visible minimization, consent, or clear boundaries on what data may leave the system, creating a real data-exposure risk.
