Context-Inappropriate Capability
Medium
- Confidence
- 89% confidence
- Finding
- The script is presented as a local parser, but `get_paddleocr_vl_paths()` treats `PADDLEOCR_VL_ALLOW_AUTO_DOWNLOAD=1` as sufficient to proceed even when local model paths are absent. In a sensitive or offline environment, this can trigger unexpected network/model-fetch behavior through the downstream library, violating deployment assumptions and increasing supply-chain and data-exposure risk.
