Vague Triggers
Medium
- Confidence
- 87% confidence
- Finding
- The README states the skill is 'automatically invoked' when a matching task is detected, but does not define the trigger conditions or scope. That ambiguity can cause an agent or user to send unintended prompts or sensitive text to the remote service, increasing the risk of over-broad activation and privacy-impacting data disclosure.
