Intent-Code Divergence
Medium
- Confidence
- 96% confidence
- Finding
- The architecture text presents contradictory security behavior around whether remote API features are disabled by default, while other sections state the API is enabled by default with a built-in key. In a security control, this can mislead operators into believing the skill is offline-only when it may actually make network requests, creating unintended data exposure and trust-boundary violations.
