Intent-Code Divergence
- Category
- Not specified by scanner
- Confidence
- 93% confidence
- Finding
The skill claims that risk code and unsafe dependencies were removed, yet it still explicitly declares the
exectool and directs the agent to use a bridge server script and API execution flow. This creates a trust mismatch: operators may lower scrutiny based on the safety claims while the skill still enables command execution and external process interaction, which materially increases attack surface.- Content
