Intent-Code Divergence
Medium
- Confidence
- 94% confidence
- Finding
- The skill is presented as a read-only Stripe access skill, but its safety guidance explicitly allows write operations whenever a user asks. Because it uses a Stripe secret or broadly scoped restricted key and documents direct API authentication, this weakens the intended safety boundary and can enable destructive or financially sensitive actions such as refunds, payouts, transfers, or account changes.
