Vague Triggers
Medium
- Confidence
- 94% confidence
- Finding
- The manifest sets `allow_implicit_invocation: true`, which allows the skill to be auto-selected without an explicit user request. In a skill that triggers external data-collection actions and can handle API-token configuration or task submission, broad implicit activation increases the chance of unintended invocation, over-collection, or execution on ambiguous prompts.
