Vague Triggers
Medium
- Confidence
- 89% confidence
- Finding
- The README says the agent should run the scanner 'after any deploy' and that adding SKILL.md lets the agent pick it up automatically. That activation trigger is broad enough to cause routine, repeated invocation without an explicit per-run approval step, which can lead to unintended outbound scans, noisy traffic against production targets, and accidental use against the wrong URL if deployment context is mis-set.
