Intent-Code Divergence
High
- Confidence
- 97% confidence
- Finding
- The skill claims file access is restricted to the project directory, but its documented execution model uses `--permission-mode bypassPermissions`, which grants broad write capability and relies on an optional write-protection plugin. This creates a mismatch between stated safeguards and actual behavior, increasing the chance that an agent or delegated CLI modifies unintended files outside the project boundary.
