Description-Behavior Mismatch
Medium
- Confidence
- 96% confidence
- Finding
- The README promises mandatory guardrail checks before every operation, but the documented design explicitly allows fail-open behavior when guardrail status is unavailable and only refreshes enforcement on a periodic cron interval. This creates a real enforcement gap where an agent can continue operating after telemetry or polling failures, or overspend between cron ticks, undermining the claimed safety control.
