Intent-Code Divergence
Medium
- Confidence
- 93% confidence
- Finding
- The documentation presents 'no external downloads at install time' as a security assurance, while the actual installation path requires fetching the package from PyPI or npm first. This is materially misleading because users may infer a stronger supply-chain guarantee than actually exists, reducing scrutiny of the package source and installer trust boundary.
