Description-Behavior Mismatch
Medium
- Confidence
- 94% confidence
- Finding
- The observer is not limited to passive monitoring: it explicitly instructs the LLM to create or update files under INSTINCTS_DIR based on project observations, then archives the source observations. That gives an autonomous model a persistent write path into the project state without human review, which can lead to integrity issues, prompt-driven poisoning, or propagation of unsafe instructions into future runs.
