Missing User Warnings
Medium
- Confidence
- 89% confidence
- Finding
- The README explicitly instructs users to visit an external configuration page, generate a config there, and paste the result back into the chat. In an agent workflow, that can cause sensitive business data, chart labels, metrics, or styling metadata derived from private datasets to be disclosed to a third-party site or copied back into a broader conversation context without any warning, review step, or data-minimization guidance.
