Intent-Code Divergence
Medium
- Confidence
- 92% confidence
- Finding
- The skill claims command execution should be restricted and user input should not be interpolated into command lines, yet elsewhere documents callback URLs, webhooks, external API integration, and command execution features without enforceable constraints. In an exec-capable skill focused on browser automation, this mismatch can enable data exfiltration to attacker-controlled endpoints or unsafe command/network behavior if downstream implementations trust user-supplied destinations.
