Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The workflow instructs the agent to upload local screenshot evidence files to a third-party site without any explicit user consent, privacy notice, or confirmation that the files contain only intended data. Because screenshots can include call signs, timestamps, account details, or unrelated desktop content, this creates a real risk of unintended data disclosure during automated submission.
