Vague Triggers
Medium
- Confidence
- 91% confidence
- Finding
- The README advertises very broad agent-trigger phrases such as 'Check workspace health' and 'What's taking up disk space?', which can overlap with ordinary user requests and cause the skill to be invoked in contexts the user may not have intended. Because this skill performs filesystem inspection across the workspace and surfaces file paths, recent changes, and storage details, ambiguous invocation increases the risk of unintended disclosure of local metadata and overbroad execution.
