Vague Triggers
Medium
- Confidence
- 88% confidence
- Finding
- The README states the skill is 'automatically invoked' when a matching task is detected, but provides no clear trigger boundaries, consent requirements, or examples of safe invocation conditions. For a skill that sends prompts to a remote paid LLM gateway, overly broad auto-invocation can cause unintended transmission of sensitive user data and unexpected payment attempts.
