Context-Inappropriate Capability
Medium
- Confidence
- 94% confidence
- Finding
- This package declares outbound/network and server-side capabilities (axios, ws, express, cors, helmet, compression) that are not clearly justified by the stated purpose of a local WinForms-to-Qt migration guidance tool. Extra network-facing functionality expands the attack surface and, if implemented, could enable data exfiltration, remote control channels, or unintended exposure of analyzed source code.
