Intent-Code Divergence
Medium
- Confidence
- 95% confidence
- Finding
- The script repeatedly claims it is "100% safe/compliant" and presents trust-signaling language such as "ClawHub合规认证" while also transmitting user-specific results to an external Feishu webhook. Even if the webhook use is intended functionality, the undisclosed outbound transmission and exaggerated safety claims can mislead reviewers and users about the skill's actual data flows and trust boundaries.
