Missing User Warnings
Medium
- Confidence
- 88% confidence
- Finding
- The README instructs users to source a local env file and immediately make authenticated requests to third-party APIs, but does not warn that secrets are being loaded or that user input/location data will be transmitted externally. This can lead to unintended credential exposure in subprocess environments and uninformed exfiltration of sensitive data such as API keys, city queries, and derived location information to external services.
