Intent-Code Divergence
Medium
- Confidence
- 89% confidence
- Finding
- The skill claims user input should not be concatenated into command parameters, yet its documented shell workflows interpolate variables directly into curl payloads and command arguments. In an MD+EXEC skill, this inconsistency is dangerous because an agent may map untrusted user-provided values into shell context, creating command-injection risk or malformed requests that exfiltrate data.
