Description-Behavior Mismatch
Medium
- Confidence
- 97% confidence
- Finding
- The skill description states 'Zero external dependencies', but the code will download a word list from the internet when generating passphrases. This is dangerous because it creates undisclosed network behavior, introduces supply-chain and integrity risks from remote content, and can violate user expectations in environments where secret-handling tools are expected to remain fully local.
