Intent-Code Divergence
Medium
- Confidence
- 93% confidence
- Finding
- The footer states that 'The AI agent never sees your keys,' but this UI explicitly collects raw secret values and the Supabase service_role key through bound inputs and passes them via event callbacks/state. That creates a misleading security claim that can cause operators to trust the system with highly privileged credentials under false assumptions.
