Intent-Code Divergence
Medium
- Confidence
- 97% confidence
- Finding
- The skill explicitly says to never hardcode API keys, but its primary example uses a literal key string in source code. This normalizes unsafe secret handling and increases the chance that users or downstream agents will paste real credentials into scripts, shell history, logs, or saved files where they can be exposed.
