Intent-Code Divergence
Medium
- Confidence
- 97% confidence
- Finding
- The skill documentation makes concrete security assurances such as protection against API key leakage, data leakage, unauthorized access, and code injection, but SKILL.md itself does not implement or enforce those controls. This can mislead users and downstream agents into overtrusting the skill, causing them to process sensitive data or execute the skill in riskier contexts without verifying the actual protections of the external connector service.
