Intent-Code Divergence
Medium
- Confidence
- 94% confidence
- Finding
- The help text claims privileged package-manager commands require the --auto-install flag, but the code also honors the AUTO_INSTALL environment variable. This can mislead operators into believing execution is disabled when an inherited environment variable could still permit package installation after prompt confirmation.
