Missing User Warnings
Medium
- Confidence
- 98% confidence
- Finding
- The code sends user-supplied medical question content to an external remote API endpoint, and the surrounding flow also returns/stores associated metadata alongside the request context without any built-in disclosure, consent, minimization, or redaction safeguards. In a medical context, prompts can contain sensitive health information, so silent transmission to a third-party or centralized service creates a significant confidentiality and compliance risk.
