Vague Triggers
Medium
- Confidence
- 92% confidence
- Finding
- The trigger phrase "environment setup" is broad enough to match many generic user requests, which can cause the skill to activate unexpectedly and perform repository scanning or inspect `.env`-related files without the user intending to invoke this specific behavior. In a skill that enumerates environment variables and validates secret-bearing files, overbroad activation increases the chance of unintended sensitive-data exposure in agent context.
