Intent-Code Divergence
Medium
- Confidence
- 91% confidence
- Finding
- The skill claims command execution should be limited to a whitelist, but its own documentation advertises broad `gh` capabilities including direct API access and webhook management. In an agent context with `exec` enabled, this mismatch can normalize unsafe execution patterns and lead to unauthorized remote state changes, data access, or exfiltration through user-influenced `gh api` usage.
