Vague Triggers
Medium
- Confidence
- 94% confidence
- Finding
- The skill advertises activation whenever the user mentions GitHub and Slack, or any two dev tools together, which is far broader than a narrowly scoped intent trigger. In practice this can cause the skill to engage on incidental conversations and pull in cross-tool context or perform actions the user did not explicitly request, increasing the chance of unintended data access or message delivery.
