Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The script base64-encodes document contents and sends them to a third-party OCR service, but it does not present an explicit warning or confirmation at the point of use that sensitive document contents will leave the local environment. In an agent skill context, users may reasonably assume local processing, so this creates a meaningful data disclosure risk for confidential PDFs, IDs, contracts, or internal records.
