Missing User Warnings
Medium
- Confidence
- 87% confidence
- Finding
- The example explicitly sends business data and a bearer token to a third-party API without any disclosure, consent flow, or warning about external transmission. This creates a real risk of users exposing sensitive operational data or credentials to a remote service they may assume is local or trusted by default.
