Intent-Code Divergence
Medium
- Confidence
- 95% confidence
- Finding
- The skill claims it avoids interpolating user input into shell commands, but the examples repeatedly embed package names and versions directly into curl, npm, and shell contexts. In an agent skill with exec permission, unsanitized or weakly validated input can become shell metacharacter injection or malformed request injection, leading to unintended command execution or exfiltration.
