Intent-Code Divergence
Medium
- Confidence
- 96% confidence
- Finding
- The skill claims it only reads and writes within BASE_DIR, but its own path-resolution instructions dereference locations under the user's home directory to find that base. Contradictory scope rules weaken trust boundaries and can normalize access to home-directory paths, making it easier for an agent to read or write outside the intended project area if path handling is wrong or symlinks are abused.
