Description-Behavior Mismatch
Medium
- Confidence
- 90% confidence
- Finding
- In continuous mode, the code automatically calls sendMessage(continuousText) after a short review timeout, which goes beyond merely inserting transcribed text into the input field. This can cause unintended prompts to be submitted without a deliberate final user action, increasing the risk of accidental command execution, disclosure of sensitive spoken content, or prompt injection into downstream agents.
