Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The README documents that user-supplied keywords, company names, or domains are sent via POST to external third-party endpoints and authenticated with a token, but it does not disclose this data transfer or provide any user-facing privacy/security warning. In a lead-generation/social media search context, queries may contain sensitive business intelligence, customer targets, or identifiers, so silent transmission to a remote service creates a meaningful privacy and trust risk.
