Description-Behavior Mismatch
Medium
- Confidence
- 90% confidence
- Finding
- The documentation promises the OCR skill is '100% local' and requires no API key, but the publish notes explicitly state that Tesseract language data is downloaded automatically at runtime. This is a security-relevant discrepancy because users may install the skill under the assumption that it performs no network activity, when in fact it fetches code/data from external sources on first run.
