Description-Behavior Mismatch
Medium
- Confidence
- 92% confidence
- Finding
- The S3 driver initializes and relies on a local FilesystemDriver cache, then uses that cache as a fallback store when S3 reads fail. In an evidence-handling context, silently degrading from object-locked remote storage to mutable local storage undermines integrity guarantees, chain-of-custody expectations, and can cause users to rely on evidence that no longer has the same tamper-resistance or central audit properties.
