Vague Triggers
Medium
- Confidence
- 91% confidence
- Finding
- The skill defines a very broad activation phrase, 'ponytail-review, repo-wide', without clear constraints on who can invoke it, in what contexts it should run, or what confirmation is required before scanning the entire repository. Broad triggers increase the chance of unintended activation, which can cause the agent to perform expansive analysis on sensitive codebases or consume excessive context/tokens when the user did not explicitly request that scope.
