Vague Triggers
Medium
- Confidence
- 89% confidence
- Finding
- The trigger phrases are broad enough to activate on ordinary requests like 'send me the file' or 'share this' without forcing confirmation about which local file should be transmitted. In a skill that can package and exfiltrate workspace files through Telegram, ambiguous invocation increases the risk of unintended disclosure of sensitive local content.
