Vague Triggers
Medium
- Confidence
- 90% confidence
- Finding
- The skill description includes very broad trigger wording such as 'Triggers on Overleaf, LaTeX sync, tex file uploads to Overleaf, or Overleaf invite acceptance,' which can cause the skill to activate in loosely related contexts without a tight user-intent boundary. Over-broad activation increases the chance an agent invokes a high-privilege skill unnecessarily, exposing browser-cookie-backed account access and write operations to unintended workflows.
