Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The documentation instructs users to interact with a remote third-party service and download logs containing game and player identifiers, but it provides no warning about data leaving the local environment or about the sensitivity of player IDs and game transcripts. The risk is increased because the documented endpoints use plain HTTP/WS rather than HTTPS/WSS, so identifiers and game data could be exposed in transit or intercepted by a network attacker.
