Context-Inappropriate Capability
Medium
- Confidence
- 95% confidence
- Finding
- The code converts LaTeX into remote image URLs hosted at math.vercel.app, causing translated document formulas to be sent to and fetched from a third-party service. This creates an unnecessary external data flow for document-derived content and introduces privacy, availability, and integrity risk if the remote service logs requests, changes output, or becomes unavailable.
