Vague Triggers
Medium
- Confidence
- 90% confidence
- Finding
- The trigger phrases include very common developer language such as "fix CI", "CI is failing", and "the build is broken", which can cause the skill to activate in ordinary conversation rather than through deliberate invocation. In this skill, unintended activation is more dangerous because the workflow encourages accessing GitHub Actions logs, running repository code via RSpec, and preparing code changes, all of which increase the chance of acting on an untrusted repo or at the wrong time.
