Description-Behavior Mismatch
Medium
- Confidence
- 97% confidence
- Finding
- The README materially misrepresents the search providers: the metadata says Baidu and Google are primary engines, while the documented implementation lists 360, Sogou, Bing CN, DuckDuckGo, Qwant, and Startpage instead. This is a security-relevant integrity issue because users and operators may make trust, privacy, censorship, compliance, or network-routing decisions based on the advertised engines, but the skill would send queries to different third-party services.
