Vague Triggers
Medium
- Confidence
- 88% confidence
- Finding
- The README states the skill is 'automatically invoked' when a matching task is detected, but provides no concrete trigger boundaries, approval requirements, or data-scope limitations. In an agent setting, ambiguous auto-invocation increases the chance that sensitive datasets are sent to the remote profiling service without clear user intent or informed consent.
