Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The script sends a phone number field to a third-party service at vnetraffic.org without any explicit notice, consent flow, or necessity check visible in the code. Even worse, if the user does not supply a phone number, it still transmits a hard-coded placeholder number, which indicates unnecessary sharing of personal-contact-style data to an external endpoint and creates privacy/compliance risk in a skill that handles vehicle lookup information.
