Intent-Code Divergence
High
- Confidence
- 96% confidence
- Finding
- The skill explicitly warns not to sign user- or externally-supplied hashes, yet later documents a raw signing endpoint that accepts an arbitrary digest. In a wallet skill, exposing raw signing materially increases the risk that an agent could authorize opaque payloads, off-protocol approvals, or signatures that users cannot meaningfully review.
