Intent-Code Divergence
High
- Confidence
- 96% confidence
- Finding
- The examples instruct the agent to validate keys, call external APIs, read masked files, and write local files, which materially expands the skill from a passive key-guardrail into an active integration and file-modification workflow. This mismatch can cause the agent to perform network and filesystem actions under a vague security-themed label, increasing the chance of unintended secret handling, unauthorized outbound requests, or unsafe file edits.
