Intent-Code Divergence
Medium
- Confidence
- 96% confidence
- Finding
- The skill advertises that commands run in a '安全沙箱' but the file only declares the `exec` tool and provides no technical control, policy, or wrapper that enforces sandboxing. This can mislead users or downstream agents into treating command execution as safe and may result in arbitrary local command execution with the agent's real privileges.
