Intent-Code Divergence
Medium
- Confidence
- 98% confidence
- Finding
- The skill claims 'production-grade secure defaults' but its quick-start examples use plain HTTP for the CSS, JS, and backend service URL. This can enable man-in-the-middle tampering, script injection, credential/session leakage, and mixed-content failures when integrated into real applications. In a developer-facing skill, insecure examples are especially risky because users often copy them verbatim into production code.
