Missing User Warnings
Medium
- Confidence
- 91% confidence
- Finding
- The script sends user-supplied search text from the --contains option to a third-party service, which can expose potentially sensitive user input off-host without clear runtime disclosure or consent. While this is expected for a joke search client, the privacy risk is real because arbitrary text entered by the user is transmitted to an external API.
