Description-Behavior Mismatch
Medium
- Confidence
- 88% confidence
- Finding
- The skill is presented as local sentiment analysis, but it can fetch the VADER lexicon at runtime if the resource is missing. That creates undeclared network behavior and a dependency on external content availability, which can violate sandboxing, privacy, or supply-chain expectations even if the code’s purpose is otherwise legitimate.
