Vague Triggers
Medium
- Confidence
- 89% confidence
- Finding
- The skill includes a ready-to-paste natural-language prompt that asks the agent to modify a local config file, which can encourage users or upstream agents to delegate a sensitive filesystem change without clear review. In this context, the change also enables a new MCP server that can execute package-managed code and initiate external account provisioning, so the broad invocation guidance increases the chance of unintended trust expansion.
