Context-Inappropriate Capability
Medium
- Confidence
- 91% confidence
- Finding
- The code loads API credentials for external AI/OCR providers and later uses them to transmit document content off-host. In the context of a PDF extractor, this is a genuine data-exposure risk if users are not clearly informed that their documents and extracted text may be sent to third parties.
