Vague Triggers
Medium
- Confidence
- 83% confidence
- Finding
- The trigger/description is broad enough that the skill may activate for generic requests to deploy or publish a site, even when the user has not clearly consented to sending code and app assets to a third-party service. In this skill’s context, unintended invocation is more dangerous because the workflow explicitly transmits files and metadata to a remote API and can create persistent public deployments.
