Intent-Code Divergence
Medium
- Confidence
- 94% confidence
- Finding
- The skill’s auth section says action endpoints require API-key authentication, but the complete-job example shows a caller-controlled `completed_by` field with no Authorization header. If implemented or followed as documented, an attacker could mark jobs complete and trigger payout or state changes by spoofing identity, creating an authorization-bypass risk around financial actions.
