Vague Triggers
Medium
- Confidence
- 87% confidence
- Finding
- The skill explicitly states that incoming messages can trigger the agent automatically, but it does not meaningfully constrain what kinds of messages are allowed to cause execution. In a messaging skill, broad auto-triggering increases the risk of prompt-injection, spam-driven activation, or unintended agent actions initiated by untrusted external parties.
