Intent-Code Divergence
High
- Confidence
- 96% confidence
- Finding
- The file repeatedly frames the skill as read-only discovery with no resource creation, yet it also directs the agent to install third-party skills via `npx skills add` or `npx clawhub install`. That mismatch can mislead operators and downstream policy engines into allowing a capability-changing action they would otherwise review, creating a trust-boundary violation and enabling unreviewed code or configuration changes in the agent environment.
