Intent-Code Divergence
Medium
- Confidence
- 92% confidence
- Finding
- The document states that all commands are read-only, but it includes `aws iam generate-credential-report`, which initiates report generation and therefore changes service state. While the action is low-risk and administrative rather than destructive, the inaccurate safety claim can mislead an agent or operator into executing a command they would otherwise review more carefully.
