Intent-Code Divergence
Medium
- Confidence
- 95% confidence
- Finding
- The permission declaration states web access is limited to localhost, but the skill explicitly supports arbitrary external vault backends such as 1Password, Bitwarden, and custom wrappers that may perform remote network access. This creates a misleading trust boundary: deployers may grant narrower egress assumptions than the skill actually needs, increasing the risk of unintended credential transmission to external services.
