Intent-Code Divergence
Medium
- Confidence
- 96% confidence
- Finding
- The script implements a `metrics` command that posts derived Jira activity data to an arbitrary external URL via `JIRA_METRICS_URL`, but the help text omits this command entirely. Hidden network-export behavior reduces transparency and informed consent, making accidental or covert exfiltration more likely in an agent skill context.
