Intent-Code Divergence
Medium
- Confidence
- 92% confidence
- Finding
- The code explicitly documents that the DAILY_CAP guard only applies in the local backend path and is not enforced in hosted mode, even though the skill’s safety model treats rate limiting as an anti-abuse control. In a job-application automation context, this creates a real policy and safety gap: an operator can execute state-changing actions without the intended code-level cap, increasing the risk of mass actions, account throttling, or anti-bot enforcement.
