Intent-Code Divergence
Medium
- Confidence
- 91% confidence
- Finding
- The skill’s data-handling section is internally inconsistent: it claims only analytics metrics are retrieved and that no content is uploaded or modified, while later steps explicitly instruct uploading media and publishing or scheduling Instagram posts. This misleading disclosure can cause users or downstream agents to underestimate the write capabilities and sensitivity of the embedded MCP token, increasing the chance of unsafe use or overbroad trust.
