Intent-Code Divergence
High
- Confidence
- 96% confidence
- Finding
- The skill claims secrets will never be printed, yet it includes examples that pass credentials in command-line arguments such as curl basic auth and tokenized URLs. Secrets in command lines can be exposed through shell history, process listings, logs, audit systems, and copied reports, directly undermining the stated safety guarantees.
