Vague Triggers
Medium
- Confidence
- 88% confidence
- Finding
- Using an empty matcher causes the hook to run on every prompt, which broadens execution scope beyond clearly justified cases and increases the chance of unintended activation. In this skill, that means a local shell script is invoked continuously during normal use, creating unnecessary attack surface and operational risk if the script path is replaced, modified, or behaves unexpectedly.
