Intent-Code Divergence
- Category
- Not specified by scanner
- Confidence
- 97% confidence
- Finding
The skill's final execution section overrides its earlier plan/template-and-canvas workflow by instructing the agent to execute terminal commands directly, step by step, against an external CLI. That creates a real security boundary violation: a user idea or prompt can be transformed into shell-invoked operations, increasing risk of unsafe command construction, unauthorized external API use, and workflow bypass that avoids the safer confirmation and structured-canvas path.
- Content
