Description-Behavior Mismatch
Medium
- Confidence
- 97% confidence
- Finding
- The skill explicitly promises that the system works completely offline, but the documented implementation falls back to loading a model from Hugging Face if the local path is missing or fails. In practice, this can cause unexpected outbound network access, undermining privacy assumptions and potentially exposing environment metadata in contexts where users rely on strict offline handling for sensitive documents.
