Intent-Code Divergence
Medium
- Confidence
- 96% confidence
- Finding
- The skill claims sensitive data will not be exposed, yet it earlier instructs enumerating environment variables matching secret-related names. Even with masking in the sample command, this encourages broad secret discovery behavior and can expose credential presence, naming, and accidental unmasked variants in real agent executions or modified commands.
