Vague Triggers
Medium
- Confidence
- 91% confidence
- Finding
- The README states that agents can use the sandbox automatically when they 'identify untrusted code execution tasks,' but it does not define explicit trigger conditions, user-consent requirements, or safety boundaries. Ambiguous auto-activation can cause an agent to invoke this skill too broadly or inappropriately, leading to unintended execution of attacker-supplied commands even if they run inside a container.
