Vague Triggers
Medium
- Confidence
- 84% confidence
- Finding
- The usage guidance is broad enough that the skill may be triggered for many ordinary business questions without clearly warning users that their prompts will be sent to a third-party API. In an agent environment, overly broad invocation increases the chance of unintended data disclosure, especially when users include sensitive business plans, financials, or internal market assumptions in a 'strategy' request.
