Intent-Code Divergence
Medium
- Confidence
- 95% confidence
- Finding
- The documentation makes conflicting safety claims: it says the skill is 'read-only' and does not send email, while earlier sections state it can generate replies and send them after user confirmation. This kind of mismatch can mislead users into granting mailbox access under false assumptions, weakening informed consent and increasing the chance of unintended outbound actions.
