Vague Triggers
Medium
- Confidence
- 85% confidence
- Finding
- The trigger text is broad enough to activate on generic requests about task status, token configuration, or troubleshooting, not just intentional Instagram profile collection. That can cause the wrong skill to engage and potentially use a stored API token or initiate external actions in contexts where the user did not clearly request this specific integration. Overbroad invocation is a security boundary issue because it increases the chance of unintended tool use.
