Intent-Code Divergence
Medium
- Confidence
- 96% confidence
- Finding
- The skill's security documentation claims HTTPS and SSL verification are enforced, but the implementation uses plain HTTP to the ComfyUI endpoint. Even though the endpoint is shown as localhost, the mismatch is security-relevant because users may rely on the stated guarantee and later adapt the URL to a remote host without transport protection, enabling interception or tampering.
