Context-Inappropriate Capability
Medium
- Confidence
- 95% confidence
- Finding
- The script initializes a remote Zhipu AI client using an API key from the environment, establishing the capability to export local document contents to a third-party service. In this file, that capability is actually exercised later on table, context, and image data, so the concern is not merely theoretical: sensitive local data may be transmitted off-host without access control, minimization, or consent flow.
