Intent-Code Divergence
Medium
- Confidence
- 95% confidence
- Finding
- The skill claims command execution is limited to a whitelist, but the manifest only exposes a generic exec capability and provides no concrete whitelist, validation logic, or enforcement boundary. In an agent context, this mismatch can cause operators or downstream systems to over-trust the skill and allow arbitrary shell execution, which is especially dangerous for a tool that may run inside developer workspaces with source code, credentials, and Git remotes available.
