Intent-Code Divergence
Medium
- Confidence
- 88% confidence
- Finding
- The README documents a JSONP relay that uses <script> tags to bypass the iframe sandbox and load content from external infrastructure, which undermines the stated isolation model. Even if presented as a feature, this creates a trust-boundary break: untrusted or mutable off-chain content can execute in the page context, enabling code injection, phishing UI, or malicious transaction prompting.
