Description-Behavior Mismatch
Medium
- Confidence
- 88% confidence
- Finding
- The script silently downloads executable model content from the internet at runtime when the local model file is absent, despite presenting itself as a local video-processing tool. This expands the trust boundary to the network and remote storage service, creating supply-chain and privacy risks if the download is intercepted, replaced, or simply unexpected in restricted environments.
