Intent-Code Divergence
High
- Confidence
- 99% confidence
- Finding
- The file hardcodes a long-lived HMAC secret directly in source and uses it to generate request signatures. Even though this is presented as a validator for example payloads, embedding a real signing key in a distributed skill undermines the documented security model of environment-managed secrets and allows anyone with the skill contents to mint valid signatures for the covered API contract if the same secret is accepted by the bridge.
