Vague Triggers
Medium
- Confidence
- 87% confidence
- Finding
- The trigger phrase is very broad and can activate on generic requests about tracing flows or documenting pipelines, which increases the chance the skill runs in situations the user did not explicitly intend. While the skill itself is documentation-oriented and does not contain obviously dangerous instructions, overbroad activation can cause unnecessary codebase exploration and external tool invocation, expanding exposure of repository structure and data-flow details.
