Vague Triggers
Medium
- Confidence
- 88% confidence
- Finding
- The trigger phrases are broad enough that the skill could activate on generic requests like 'share this' or 'get a link' without the user clearly intending to publish content to an external third-party service. In this skill, unintended activation is more dangerous because activation leads directly to uploading user-generated HTML to a remote endpoint, potentially causing data disclosure or unauthorized publication.
