Description-Behavior Mismatch
Medium
- Confidence
- 95% confidence
- Finding
- The README documents that the skill defaults to Baidu OCR, which sends image content to an external cloud service. That materially expands the skill's behavior from local image-to-code conversion into networked data transfer, creating privacy and data-governance risk for potentially sensitive images.
