Vague Triggers
Medium
- Confidence
- 92% confidence
- Finding
- The manifest description uses broad trigger language such as 'any videographer service request,' which can cause the skill to activate in situations where the user did not clearly intend to use this third-party booking workflow. Because the skill connects to an external MCP endpoint and can lead to booking actions, over-triggering increases the risk of unintended data sharing or transactional actions.
