Intent-Code Divergence
Medium
- Confidence
- 96% confidence
- Finding
- The document claims API keys are managed securely via environment variables and not exposed, but multiple examples show the API key being returned in skill output. In an agent environment, structured outputs are often logged, cached, or forwarded, so returning live credentials materially increases the risk of secret leakage and downstream account compromise.
