Intent-Code Divergence
Medium
- Confidence
- 98% confidence
- Finding
- The code is documented as an 'OpenAI Whisper STT Provider' but actually sends audio and credentials to a third-party SkillBoss endpoint. This is dangerous because operators may believe audio is going directly to the named upstream provider and may not realize sensitive voice data is being routed through an intermediary with different privacy, retention, and trust boundaries.
