Intent-Code Divergence
Medium
- Confidence
- 95% confidence
- Finding
- The document states 'No telemetry, analytics, or external API calls' in its security section, but later recommends using Pinata HTTPS endpoints and arbitrary https:// or Arweave URLs for metadata handling. This is a security-relevant contradiction because users may trust the earlier claim and underestimate that the workflow can involve third-party network services, metadata hosting, and disclosure of content or credentials such as a Pinata JWT.
