Intent-Code Divergence
High
- Confidence
- 97% confidence
- Finding
- The documentation states the tool runs in read-only mode and that write features require credentials, but it also documents unauthenticated POST /api/digests and PUT /api/config endpoints. This mismatch can mislead operators into deploying the service with unsafe assumptions, leaving system-changing functionality exposed without access control.
