Intent-Code Divergence
Medium
- Confidence
- 90% confidence
- Finding
- This section makes concrete security and privacy claims such as sanitization, validation, and fully local processing, but the SECURITY.md file itself does not provide evidence that these controls actually exist or are consistently enforced. Overstated assurances can cause users and reviewers to trust generated prompts or the skill's handling of data more than warranted, increasing the chance of unsafe use or missed defects.
