Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The script transmits user-supplied text and voice-style instructions to a third-party cloud API, but it does not clearly disclose this data egress at runtime or require explicit user confirmation. This can expose sensitive or confidential content if callers assume the synthesis happens locally, especially in an agent context where arbitrary user prompts may be forwarded automatically.
