Vague Triggers
Medium
- Confidence
- 90% confidence
- Finding
- The README states the skill is 'automatically invoked' when a matching task is detected, but gives no concrete trigger boundaries, consent model, or safeguards. In an agent ecosystem, ambiguous auto-invocation can cause unintended routing of user prompts or code to this remote skill, increasing the chance of silent data disclosure or unexpected paid requests.
