Intent-Code Divergence
Medium
- Confidence
- 90% confidence
- Finding
- The comment is misleading because the installer does perform network download and archive extraction by invoking shell commands through execSync. More importantly, it downloads and installs a release artifact from the network without any integrity verification such as a checksum or signature check, so a compromised release, account, or transport endpoint could result in arbitrary code being installed on the user's machine.
