Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The README explicitly states that natural-language user queries are rewritten via an internal LLM call and then sent to the Ceramic Search API, but it gives no warning that user prompts may be disclosed to third-party services. In an agent setting, users may submit sensitive prompts assuming local handling, so undisclosed external transmission creates a real privacy and data-governance risk.
