Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The code sends aggregated wiki content to an LLM endpoint (`http://localhost:11434/v1`) without any consent, disclosure, classification, or filtering step. Even though the default endpoint is local, this still creates a data-exposure path because wiki entries may contain sensitive internal content, and the endpoint is configurable, so data could be redirected to a remote service or logged by another local process.
