Vague Triggers
Medium
- Confidence
- 87% confidence
- Finding
- The skill’s trigger guidance is broad enough that an agent may invoke internet exposure based on casual phrases like 'share this' or 'send me the link' without first confirming that the user understands a public URL will be created. In this skill’s context, that is dangerous because its primary action exposes localhost services or local files to external access, which can unintentionally disclose sensitive data or internal apps.
