Vague Triggers
Medium
- Confidence
- 83% confidence
- Finding
- The trigger phrase "audit this skill:" accepts pasted content without defining clear boundaries, size limits, or trusted input scope. In a security-auditing skill, this can enable prompt-injection or content-smuggling attacks where adversarial markdown instructs the model to ignore its guardrails, making the skill more dangerous because it is explicitly designed to process untrusted text.
