Vague Triggers
Medium
- Confidence
- 79% confidence
- Finding
- The README encourages broad, natural-language invocations such as "clean this email list" and "verify jane@acme.com" without stating scope limits, confirmation requirements, or privacy guardrails. In an agent setting, this can lead to the skill being triggered on sensitive user-provided datasets and sending emails to a third-party API more readily than the user may realize.
