Intent-Code Divergence
Medium
- Confidence
- 98% confidence
- Finding
- The security note makes materially inaccurate safety claims: several examples do not use jq and instead interpolate variables directly into curl -F arguments and shell constructs. Misstating the safety properties of the skill can cause downstream agents or users to overtrust the examples and reuse unsafe patterns, increasing the chance of shell argument injection or accidental mishandling of untrusted input.
