Intent-Code Divergence
Medium
- Confidence
- 95% confidence
- Finding
- The script tells users the file never leaves their machine, but it still sends sensitive file-derived metadata to a remote service, including the SHA-256 hash and filename. That is a misleading privacy/security claim because hashes and filenames can still reveal information, enable correlation, or expose confidential document names.
