Description-Behavior Mismatch
Medium
- Confidence
- 87% confidence
- Finding
- The CLI persists the full fetched Douyin results to a local JSON file without an explicit opt-in or clear disclosure to the user. Even if intended for convenience/debugging, this creates unnecessary local data retention and can expose scraped content or metadata to other local users, backups, or downstream processes, which exceeds the apparent read/analyze behavior of the skill.
