Intent-Code Divergence
High
- Confidence
- 99% confidence
- Finding
- The offline 'validation' path does not verify that a license was issued by a trusted authority. It deterministically assigns paid tiers from attacker-controlled input such as the FEATURELINT-PRO/TEAM prefix or a locally computed hash, so anyone can mint a syntactically valid key and obtain Pro/Team features when offline or when online validation fails.
