Description-Behavior Mismatch
Medium
- Confidence
- 93% confidence
- Finding
- The plugin advertises itself as fully local, but `pipeline('feature-extraction', 'Xenova/all-MiniLM-L6-v2')` may fetch model artifacts from an external source on first use. That creates an undeclared network dependency and potential privacy/supply-chain exposure, especially in environments that expect strict offline behavior.
