Vague Triggers
Medium
- Confidence
- 91% confidence
- Finding
- The README instructs users to invoke the skill with a very broad natural-language phrase ('帮我审核 GitLab 仓库的 MR'), which can plausibly overlap with ordinary requests and cause unintended activation. In an agentic workflow that performs external actions like fetching MR data, generating reports, and emailing contributors, accidental triggering can lead to unwanted processing and data disclosure.
