Intent-Code Divergence
Medium
- Confidence
- 93% confidence
- Finding
- The credential scope states that env vars are accessed via `process.env` or `os.environ.get()` in generated code only. However, the skill body later contains direct `process.env` accesses in embedded validation logic such as `OPENROUTER_API_KEY`, `VERCEL_TOKEN`, `SUPABASE_URL`, and `SUPABASE_ANON_KEY`, which contradicts the narrow claim about where credential access occurs.
