Intent-Code Divergence
Medium
- Confidence
- 95% confidence
- Finding
- The document makes strong claims that all user input is validated and safely escaped, but later explicitly warns that passing direct user input to the script is unsafe. This inconsistency can cause operators or downstream agents to overtrust the skill's safety properties and use it in risky ways, leading to malformed requests, injection into generated JSON, or accidental misuse of privileged API credentials.
