Intent-Code Divergence
Medium
- Confidence
- 95% confidence
- Finding
- The code actively performs HTTPS man-in-the-middle interception by generating a CA and signing per-host certificates, enabling decryption and inspection of plaintext traffic. In an agent skill context, this is highly sensitive because it can capture prompts, tokens, API keys, session cookies, and other confidential data from all proxied HTTPS connections.
