Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The README explicitly advertises support for remote image URLs but does not warn users that providing a URL may cause the service to fetch or otherwise process externally hosted content, potentially disclosing the image location and associated metadata to verging.ai. This can surprise users handling private, internal, or signed URLs and may lead to unintended data exposure or privacy violations.
