Vague Triggers
Medium
- Confidence
- 90% confidence
- Finding
- The skill activates on very broad coding-related requests and instructs dispatch to VS Code Copilot for execution, which can lead to unintended delegation of sensitive or high-risk tasks without clear scope limits. In context, this is more dangerous because the downstream agent is described as able to edit files and run commands, so ordinary-looking prompts could trigger system-modifying actions.
