Description-Behavior Mismatch
Medium
- Confidence
- 94% confidence
- Finding
- This wrapper does more than invoke a search tool: it conditionally builds code and, if that fails, downloads and installs a prebuilt executable from GitHub releases. That creates an unexpected software installation/update path with remote code execution implications, which exceeds the stated search-only purpose and increases supply-chain risk.
