They seem to consider any use of an SDK or library to be "data sharing". For example, if an app uses OkHttp (an open-source HTTP client library) [1] then it counts as data sharing. That doesn't seem right...
Classing OkHttp as "Medium Risk" is ridiculous (especially since under the hood it's been the default HTTP library on Android since something like 5.0). That alone signals that the authors don't have the the skills or expertise to carry out this study.
It's a shame - since I bet there is definitely data being leaked places it shouldn't be in apps like these, and a proper investigation would be interesting.