Vague Triggers
Medium
- Confidence
- 91% confidence
- Finding
- The skill advertises very broad triggers such as 'attach this screenshot to the PR/issue' and generally applies whenever an image is generated or saved. That can cause the agent to upload files without a sufficiently explicit user decision, which is risky because the destination is a public CDN and the action transfers local artifacts off-system.
