Vague Triggers
Medium
- Confidence
- 93% confidence
- Finding
- The README states the skill is 'automatically invoked' when a matching task is detected, but provides no trigger boundaries, approval requirements, or examples of safe versus unsafe invocation. For a skill that sends user input to a remote paid service, ambiguous auto-invocation increases the chance of unintended data disclosure and unexpected billing.
