Intent-Code Divergence
Medium
- Confidence
- 91% confidence
- Finding
- The header comment says there is no network activity, but the script emits instructions directing an agent to WebFetch multiple external URLs. In an agent-skill context, generated prompts are effectively operational behavior, so this mismatch can mislead reviewers and downstream policy checks about the skill’s real external-data access and trust boundary.
