Intent-Code Divergence
Medium
- Confidence
- 90% confidence
- Finding
- The skill advertises a generic `exec` capability while only documenting a conceptual whitelist restriction, with no concrete enforcement mechanism in the skill definition. This creates a dangerous mismatch: users or downstream agents may trust the safety claim and invoke shell execution in contexts where user-controlled input, repository content, or generated commands can lead to arbitrary command execution or destructive local actions.
