Intent-Code Divergence
Medium
- Confidence
- 92% confidence
- Finding
- The skill metadata claims risk code and external dependencies were removed, but the skill still requests the powerful `exec` tool and references a bridge server script for controlling a local EasyEDA client. That mismatch is security-relevant because it can mislead reviewers and users into underestimating the trust and execution boundary, increasing the chance that command execution is granted without appropriate scrutiny.
