Intent-Code Divergence
Medium
- Confidence
- 80% confidence
- Finding
- The workflow examples require passing a phone number to several commands even though the formal command definitions do not include that parameter. In security-sensitive flows such as order lookup, cancellation, change, and refund, contradictory interface documentation can cause implementers or agents to collect and transmit extra personal data unnecessarily or to call the wrong operation with unintended arguments.
