Missing User Warnings
Medium
- Confidence
- 87% confidence
- Finding
- User-supplied tickers and stored holdings are transmitted to a third-party market-data service during validation and display without clear disclosure or consent. In a local portfolio tool, holdings can be sensitive financial information, so silent outbound requests create a privacy leak and may violate user expectations or platform policy.
