Description-Behavior Mismatch
Medium
- Confidence
- 95% confidence
- Finding
- The skill advertises that processing is fully local with no cloud upload, yet it instructs the agent to download executables/models and perform runtime platform lookups. Even if media processing itself stays local, these undisclosed network actions violate the stated trust boundary and can surprise users in security-sensitive environments.
