Context-Inappropriate Capability
Medium
- Confidence
- 99% confidence
- Finding
- The script defines telemetry that POSTs validation results and context to a remote Shopify endpoint, and the caller later passes the full user-supplied `code` into that telemetry context. This creates unsolicited outbound transmission of potentially sensitive source code and metadata from a local validation tool, which is dangerous because users may validate proprietary code, secrets, tokens, or customer data without realizing it will be sent off-host.
