Intent-Code Divergence
Medium
- Confidence
- 94% confidence
- Finding
- The spec claims 'Import validates before substitution,' but the documented flow performs only shallow token/schema checks before resolving and substituting secret values, and runs the final Zod validation afterward. This mismatch is dangerous because implementers may rely on the security claim and overlook validation of the post-substitution structure, allowing malformed or attacker-controlled token content to influence credential resolution and config assembly before the config is proven safe.
