Intent-Code Divergence
Medium
- Confidence
- 95% confidence
- Finding
- The documentation explicitly states that agents can self-register via `/admin/agents` with no authentication, while the rest of the design relies on agent identity and scope for access control. In a system where identity appears to be client-supplied, unauthenticated registration and likely unauthenticated identity assertion enable spoofing, rogue agent creation, and erosion of the trust model behind ownership and scope enforcement.
