Intent-Code Divergence
Medium
- Confidence
- 97% confidence
- Finding
- The safety section incorrectly states that untagged actions are read-only, but the listed untagged actions include credential-revealing and state-changing/authentication operations such as get_app_token, get_team_api_token, client_login, store_team_api_token, and subscription_flow. This misclassification can cause an agent to execute sensitive actions without confirmation, exposing secrets or altering authentication state under the assumption that they are safe reads.
