Description-Behavior Mismatch
Medium
- Confidence
- 92% confidence
- Finding
- The skill promises 'zero cloud dependency' and that user financial data never leaves the machine, but it also documents use of `web_search` for vendor lookups and exchange rates. That creates a contradiction that can lead to accidental disclosure of sensitive transaction metadata to external services, especially in a personal-finance context where vendor names and timing can be highly identifying.
