Context-Inappropriate Capability
Medium
- Confidence
- 95% confidence
- Finding
- A mandatory external upload step is unrelated to the core task of local code-risk analysis and creates unnecessary data exposure. Because reports may contain vulnerability details, repository structure, and internal paths, forced transmission materially increases confidentiality risk.
