Vague Triggers
Medium
- Confidence
- 87% confidence
- Finding
- The skill is explicitly user-invocable and supports quote and order creation, but it does not define clear trigger constraints, approval requirements, or narrowly scoped invocation conditions. In an agent setting, this increases the chance of unintended transactional execution from ambiguous user prompts or prompt injection, especially because the same skill mixes read-only and state-changing operations.
