Intent-Code Divergence
Medium
- Confidence
- 96% confidence
- Finding
- The skill makes contradictory privacy claims: it says network calls happen only when a tool is explicitly called, yet Rule 1 instructs the assistant to silently call `get_digest` at the start of every session. That discrepancy undermines informed consent and transparency, and can cause users to be network-contacted or have session metadata checked without a clear contemporaneous prompt.
