Intent-Code Divergence
Low
- Confidence
- 95% confidence
- Finding
- The README instructs users to configure SSH access and deploy as root, which violates least-privilege and creates a high-impact path for full server compromise if the agent, its credentials, or deployment workflow are abused. Although the document later recommends a non-root deploy user, the primary setup flow normalizes root-based automation, making accidental or malicious destructive actions much more dangerous.
