Intent-Code Divergence
Medium
- Confidence
- 89% confidence
- Finding
- The skill claims command execution is restricted to a whitelist, but the documentation advertises broad exec-capable workflows including browser automation, scheduling, alerts, and arbitrary CLI-style operations. This mismatch can mislead users and downstream agents about the actual trust boundary, increasing the chance that unsafe commands or data-handling flows are executed under a false assumption of restriction.
