Intent-Code Divergence
Medium
- Confidence
- 92% confidence
- Finding
- The skill declares `exec` capability and later claims command execution is restricted to a whitelist, but the document never defines any actual command boundary, whitelist source, or enforcement mechanism. This mismatch can mislead operators into overtrusting the skill and approving workflows that may permit arbitrary or unintended command execution through the agent runtime.
