Intent-Code Divergence
Low
- Confidence
- 95% confidence
- Finding
- The documentation states the package is pinned to version 1.0.9, but both the manifest and examples use @latest. Installing a CLI at @latest makes the executed code mutable over time, defeating reproducibility and supply-chain review; a future compromised or breaking release could be pulled automatically by users or agents.
