Context-Inappropriate Capability
High
- Confidence
- 94% confidence
- Finding
- The script transmits bookmark URLs and associated tweet text to the OpenAI API for summarization whenever an API key is present. This is a real data-exfiltration/privacy risk because bookmark contents may include sensitive research, private links, or personal content, and there is no consent gate, minimization, or policy enforcement around what leaves the local environment.
