Vague Triggers
Medium
- Confidence
- 90% confidence
- Finding
- The trigger phrases and examples are broad enough to match ordinary requests about sending files, which can cause the skill to activate in contexts where the user did not explicitly consent to local file exfiltration. Because the skill is designed to upload arbitrary local files into a chat, accidental or ambiguous invocation materially increases the risk of unintended disclosure of sensitive data.
