Missing User Warnings
Medium
- Confidence
- 87% confidence
- Finding
- The script can persist extracted applicant PII to any path supplied via --out, and the payload includes raw candidate values rather than only masked previews. In the context of a credit-card application helper, this creates a real privacy and data-handling risk because sensitive profile data may be written to disk without sufficient guardrails, explicit persistence consent, path restrictions, or encryption.
