Vague Triggers
Medium
- Confidence
- 90% confidence
- Finding
- The trigger list includes broad, common phrases such as 'is this token safe', 'audit contract', and 'safe to buy', which can cause the skill to activate in situations where the user did not clearly intend to initiate a paid external scan. In this skill, unintended invocation is more concerning because each scan can trigger an x402 payment and send token/query data to third parties.
