Vague Triggers
Medium
- Confidence
- 90% confidence
- Finding
- The skill advertises a very broad natural-language capability ('Control a Mac through natural language') without clear scoping boundaries, which can cause overbroad or unintended invocation for sensitive actions. In this context, the risk is amplified because the underlying tool can read the screen, type, click, and operate arbitrary applications, so accidental activation could lead to privacy exposure or unwanted system changes.
