Intent-Code Divergence
Medium
- Confidence
- 93% confidence
- Finding
- The skill claims command execution is limited by a whitelist or safe sandbox, yet the declared tool set includes unrestricted exec and the document provides no enforceable mechanism for those restrictions. This can mislead users or downstream agents into trusting shell execution that may actually run arbitrary commands, increasing the chance of filesystem, credential, or environment compromise.
