Description-Behavior Mismatch
Medium
- Confidence
- 96% confidence
- Finding
- The skill’s description implies document text extraction, but the implementation sends full document contents to a third-party cloud API for processing. This creates a confidentiality and data-governance risk because users may assume local processing and unknowingly upload sensitive PDFs or DOCX files externally.
