Intent-Code Divergence
High
- Confidence
- 97% confidence
- Finding
- The document claims a 'zero-exposure' design where the AI cannot see credential content, but the provided code reads a local token, calls the sensitive retrieval API, parses the decrypted response, and returns credential material to the caller. In an agent skill context, this creates a direct path for agent-authored code to access secrets, undermining the stated trust boundary and increasing the risk of credential disclosure or misuse.
