Intent-Code Divergence
Medium
- Confidence
- 94% confidence
- Finding
- The skill first declares that canon is bundled in local skill-relative files, but later instructs the agent to read from an external absolute Windows path. That inconsistency can cause the agent to access files outside the skill package, expanding the trust boundary and potentially exposing unrelated local data if path handling or retrieval behavior is permissive.
