Vague Triggers
Medium
- Confidence
- 85% confidence
- Finding
- The pipeline manifest defines a CLI skill but does not declare any explicit trigger scope, allowed callers, or invocation constraints. In practice this means any context able to invoke the skill may send arbitrary stdin through to the model, increasing the chance of unintended use, abuse, or execution in contexts where users did not expect external processing.
