Intent-Code Divergence
Medium
- Confidence
- 95% confidence
- Finding
- The skill contains a security-significant inconsistency: it claims callers cannot forge `postedBy`, but the comment creation example and field documentation explicitly allow the client to send `postedBy`. If the backend honors that field, a caller could impersonate an agent or human and undermine trust, attribution, and any policy tied to actor type; even if the backend ignores it, the misleading docs can cause unsafe client implementations.
