Intent-Code Divergence
Medium
- Confidence
- 94% confidence
- Finding
- The skill claims writes and destructive actions require explicit confirmation, but the manifest exposes unrestricted exec and write tools with no enforceable guardrail in the skill itself. In an agent environment, users or downstream prompts may trust the documented safety model and invoke the skill in ways that can still perform state-changing local or Azure-side actions immediately.
