Intent-Code Divergence
Medium
- Confidence
- 93% confidence
- Finding
- The safety section gives mixed signals about networked and external actions: it says 'web_search / web_fetch' is safe to do freely, but also says to ask first for 'Anything that leaves the machine.' In practice, web access inherently sends data off-host, so this ambiguity can cause the orchestrator to autonomously transmit prompts, URLs, tokens in query strings, or workspace-derived context without explicit approval. Because this is the leader role with broad authority to coordinate and summarize owner context, the ambiguity is more dangerous than it would be in a narrower skill.
