Vague Triggers
Medium
- Confidence
- 86% confidence
- Finding
- The skill explicitly allows automatic invocation via heartbeat or cron, but the trigger conditions are broad and not bounded by clear user-consent, scope, or rate-limit requirements. In an agent environment, this can cause unintended repeated execution, unsolicited reads/writes to goals files, and surprise workflow changes, especially when combined with automatic updates to `goals/GOALS.md` and archive/retro files.
