Intent-Code Divergence
Medium
- Confidence
- 97% confidence
- Finding
- The embedded skill reference states that all scans execute locally, no dependency data is sent to external servers, and scanning is offline. Earlier in the README, the documented requirements and security notes explicitly allow network access to query public CVE/OSV databases and say dependency hashes/names may be sent externally, which directly contradicts the offline/privacy claim.
