Intent-Code Divergence
Medium
- Confidence
- 90% confidence
- Finding
- The skill advertises exec capability, external callback URLs, and command-driven behavior, while its safety section only generically claims that only whitelisted commands are executed and user input is not concatenated into commands. Because no actual whitelist, argument validation rules, or callback restrictions are defined, an agent may over-trust the documentation and execute unsafe command compositions or reach attacker-controlled endpoints.
