Intent-Code Divergence
Medium
- Confidence
- 88% confidence
- Finding
- The README asserts that cookies and other sensitive information 'will not be uploaded or leaked', yet the documented workflow explicitly uses authenticated cookies and a Playwright browser session to access remote third-party sites. Even if the skill does not intentionally exfiltrate cookies, this claim is overly broad and misleading because authenticated state is necessarily transmitted to target platforms and may be exposed through browser automation, request headers, logs, crash artifacts, or misconfiguration.
