Vague Triggers
High
- Confidence
- 95% confidence
- Finding
- The skill advertises extremely broad trigger conditions such as any mention of a new feature, next step, or generic development planning, and then states it should run autonomously and decide what comes next. This creates a real prompt-routing vulnerability: normal developer conversation can unintentionally invoke a powerful orchestrator that performs multi-phase actions, increasing the chance of unauthorized repo changes, issue churn, or excessive autonomous execution.
