Vague Triggers
Medium
- Confidence
- 90% confidence
- Finding
- The activation text says to use the skill proactively for essentially any Google-related request, which is overly broad for a skill that can read mail, exfiltrate files, share documents, and delete resources. Broad auto-triggering materially increases the chance the agent invokes sensitive actions without a clear, task-specific user consent boundary.
