Intent-Code Divergence
Medium
- Confidence
- 98% confidence
- Finding
- The header explicitly claims that all requests are read-only public endpoints and that no user data is sent or stored, but the skill issues many POST requests that transmit user-supplied content such as questions, claims, portfolio holdings, URLs, strategies, and tickers to a third-party API. This is dangerous because users and platform reviewers may rely on the disclosure statement when deciding what data to provide, leading to unintended external data sharing under false assumptions.
