Vague Triggers
Medium
- Confidence
- 90% confidence
- Finding
- The invocation examples are so generic that the skill can be triggered by ordinary product-management requests without clear boundaries, creating prompt-scope confusion and unintended activation. In an agent ecosystem, this can cause the skill to intercept broad user requests and influence responses outside a narrowly intended context, which is a real security/control-plane issue even without overtly malicious content.
