Intent-Code Divergence
Medium
- Confidence
- 95% confidence
- Finding
- The skill’s security section says API access should be restricted, but the FastAPI example exposes POST and GET endpoints with no authentication or authorization checks. If deployed as documented, any reachable client could submit synthesis jobs and enumerate or retrieve outputs, creating unauthorized use and possible data exposure.
