Intent-Code Divergence
Medium
- Confidence
- 91% confidence
- Finding
- The documentation states that credentials never leave the local machine, yet the workflow explicitly requires using those credentials to authenticate to external services and CLI tools. This is dangerous because it can mislead users about trust boundaries, causing them to provide sensitive session tokens under a false assumption that no external transmission occurs.
