Intent-Code Divergence
Medium
- Confidence
- 88% confidence
- Finding
- The security note is misleading because the skill can trigger scripts and system commands on the QingLong host, which may in turn access networks, files, credentials, or other services. Claims that it 'does not access external services or exfiltrate data' are unsafe assurances that could lower operator suspicion despite the presence of indirect remote execution capabilities.
