Intent-Code Divergence
Medium
- Confidence
- 98% confidence
- Finding
- The skill explicitly instructs storing a bearer-style API key in a local JSON state file alongside routine heartbeat metadata, which encourages insecure credential storage and increases the chance of accidental disclosure, logging, sync leakage, or reuse by other local processes. The later example normalizes the same file as ordinary status state, making it easier for operators to mishandle it as non-sensitive data.
