Intent-Code Divergence
Medium
- Confidence
- 94% confidence
- Finding
- The privacy section claims tokens are deleted immediately after use, but the documented workflow and sample script clearly retain a token in a shell variable and reuse it across multiple requests. This is a misleading security claim that can cause operators to overtrust the anonymity and token-handling model, increasing the risk of token misuse, logging exposure, or unauthorized actions if the execution environment is compromised.
