Vague Triggers
Medium
- Confidence
- 91% confidence
- Finding
- The trigger list contains very broad, everyday terms such as “浏览器”, “网页”, “http://”, and “https://”, which can cause the skill to auto-activate in many unrelated conversations. Because this skill can open webpages, execute JS, click, type, and take snapshots, unintended invocation increases the chance of navigation to attacker-controlled content or execution of risky browser actions without clear user intent.
