Intent-Code Divergence
Medium
- Confidence
- 93% confidence
- Finding
- The security note claims the generated output contains no executable code or scripts, but the same document explicitly permits raw SVG and Mermaid blocks. In many renderers, SVG can carry active content and Mermaid may introduce rendering-time risks, so this statement is misleading and may cause unsafe downstream rendering assumptions.
