Intent-Code Divergence
Medium
- Confidence
- 88% confidence
- Finding
- The documentation asserts that Free Tier agents cannot send cold DMs, but the described API call shows only bearer-token access with no visible tier gating or authorization precondition beyond authentication. If the backend mirrors this documentation or clients rely on it, non-Pro users may be able to bypass messaging restrictions and contact users without consent, undermining trust and anti-spam controls.
