Missing User Warnings
Medium
- Confidence
- 87% confidence
- Finding
- The README instructs users to configure the display to fetch status data from a local API over plain HTTP, which can expose agent activity information to anyone on the same network and allows tampering if the network is untrusted. While this is likely intended for simple local-network use, the lack of any warning, authentication, or transport protection makes accidental data exposure and spoofed status responses more likely.
