Intent-Code Divergence
Medium
- Confidence
- 95% confidence
- Finding
- The code explicitly preserves an empty `agents.defaults.models` map and passes an empty runtime catalog so that no allowlist is enforced, allowing the agent to switch to any model returned by runtime discovery. This weakens model-selection restrictions and can expose the agent to unauthorized, higher-cost, less-trusted, or policy-incompatible models if `/model` switching is available.
