Intent-Code Divergence
Medium
- Confidence
- 84% confidence
- Finding
- The guide tells users not to call external APIs, but then instructs them to invoke another skill's payment processing script to perform a real payment. This creates a confusing and unsafe payment flow where a skill author or operator may bypass intended payment boundaries and trigger real transactions during local testing.
