Description-Behavior Mismatch
Medium
- Confidence
- 95% confidence
- Finding
- The skill advertises itself as fully offline and no-cloud, but the notes state that models are downloaded from HuggingFace on first run. This is dangerous because users and operators may trust the skill in restricted or air-gapped environments, leading to unexpected outbound network access, policy violations, and unreviewed third-party model retrieval.
