Intent-Code Divergence
Medium
- Confidence
- 80% confidence
- Finding
- The FAQ says the skill does not send code to external servers, but elsewhere admits Cursor CLI may transmit data to Anthropic/Claude APIs. This misleading security claim can cause users to run the skill on sensitive code under a false privacy assumption, increasing risk of unintended data exfiltration to third-party services.
