Vague Triggers
Medium
- Confidence
- 84% confidence
- Finding
- The trigger set is broad enough to invoke this skill on generic terms like "phone" and "android," which can cause the agent to select a highly privileged device-control skill in contexts where the user did not clearly request remote device manipulation. Because the skill enables shell access, app installs, file transfer, screenshots, and input injection, accidental invocation increases the chance of privacy-invasive or destructive actions on a connected device.
