Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The script sends user-supplied AI system descriptions to the external `gemini` CLI for inference without clearly warning the user that their input will leave the local environment. If those descriptions contain confidential, regulated, or personal information, this can cause unintended data disclosure to a third-party service and create privacy, compliance, or contractual risk.
