Intent-Code Divergence
Medium
- Confidence
- 92% confidence
- Finding
- The skill markets Mock as providing a clean and secure build environment, but the included custom configuration later enables network access inside the chroot via rpmbuild_networking=True and use_host_resolv=True. That mismatch can mislead users into assuming builds are isolated when build scripts may fetch remote content, exfiltrate data, or produce non-reproducible artifacts.
