Vague Triggers
Medium
- Confidence
- 89% confidence
- Finding
- The skill is described as applicable to essentially any request involving external apps and any API operation, which makes it likely to auto-trigger for broad, ordinary user requests. In this context, the skill holds a high-privilege Membrane token and can create connections, build actions, and execute operations across many third-party services, so an overly broad trigger increases the chance of unintended invocation and data transfer to an external platform.
