Description-Behavior Mismatch
Medium
- Confidence
- 93% confidence
- Finding
- The script is presented as an append-only audit ledger, but on certain outcomes it also mutates a separate governance progress file by setting recovery flags. This hidden side effect expands the component's authority from logging into state control, which can let any caller that can invoke the audit command influence governance workflow and create integrity or availability issues in downstream automation.
