Description-Behavior Mismatch
Medium
- Confidence
- 95% confidence
- Finding
- The skill is framed as a local conversion workflow, but it automatically downloads license and model artifacts from remote servers. This undermines the local-only trust model and introduces supply-chain, privacy, and availability risks if the remote source is compromised or unexpectedly contacted in sensitive environments.
