Missing User Warnings
Medium
- Confidence
- 91% confidence
- Finding
- The script takes arbitrary user-supplied text and transmits it to a backend HTTP service without any explicit notice, consent flow, or indication to the user that their prompt leaves the local agent boundary. This creates a privacy and data-handling risk, especially because the default endpoint is a hard-coded private-network address, so users may assume processing is fully local when it may be handled by another service on the network.
