Vague Triggers
Medium
- Confidence
- 94% confidence
- Finding
- The default-invocation guidance is aggressive and ambiguous, encouraging the skill to activate for a wide range of 'substantial' outputs without a precise boundary. In practice this can lead to unwanted behavior changes, excessive artifact generation, and increased attack surface if user-supplied content is embedded into HTML/JS outputs by default.
