Intent-Code Divergence
- Category
- Not specified by scanner
- Confidence
- 98% confidence
- Finding
The skill repeatedly markets the environment as safe for running untrusted code, but the same document later states the sandbox exposes the host Docker socket. Access to the host Docker daemon is effectively equivalent to privileged control over the host/container environment, so the isolation claim is materially misleading and can lead users to run hostile code under a false sense of safety.
- Content
