Intent-Code Divergence
Medium
- Confidence
- 87% confidence
- Finding
- The README gives contradictory security guidance: earlier sections describe session-level automatic token capture and header injection by the runtime, while later notes say the model will save and carry the access token itself. In an agent skill, this ambiguity can lead to insecure implementations where the model exposes, stores, or mishandles bearer tokens, increasing the chance of credential leakage or unauthorized API use.
