Intent-Code Divergence
High
- Confidence
- 95% confidence
- Finding
- The skill claims in its security checklist that it has no eval/exec or untrusted external command execution, yet the metadata explicitly grants the exec tool. This contradiction is dangerous because reviewers or users may rely on the safety claims while the skill still has a capability that can execute commands, expanding the attack surface for arbitrary local actions if later prompts or implementations use it.
