Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The code uploads the full user file to external OCR infrastructure via prepareUploadFile/PUT upload/fileParsing without any built-in notice, consent gate, or destination disclosure in this execution path. Because this skill is specifically used for scanned contracts, court documents, bills, and other potentially sensitive legal records, silent exfiltration to a third-party service creates a real confidentiality and compliance risk.
