Missing User Warnings
High
- Confidence
- 96% confidence
- Finding
- This pipeline forwards raw stdin content directly to the OpenAI API, which can expose sensitive user-provided data to an external service without any disclosure, consent flow, or input restrictions. Because stdin may contain arbitrary pasted text, users could unintentionally send secrets, personal data, or proprietary content off-system.
