Description-Behavior Mismatch
Medium
- Confidence
- 90% confidence
- Finding
- The script persistently stores fetched transcripts, source URLs, and session state under the user's home directory without any consent flow, retention notice, or minimization. Transcripts and watch history can reveal sensitive interests or private/unlisted content, so silent local retention creates a real privacy and data-exposure issue if the machine or workspace is shared or later compromised.
