Intent-Code Divergence
Medium
- Confidence
- 98% confidence
- Finding
- The setup summary explicitly states that rate limiting is included, but no rate-limiting middleware, per-route throttling, or provider-specific protection is actually configured anywhere in the instructions. In an authentication skill, this can mislead users into deploying login, signup, password reset, or OTP endpoints without brute-force and abuse controls, increasing exposure to credential stuffing, account enumeration, and resource exhaustion.
