Vague Triggers
Medium
- Confidence
- 93% confidence
- Finding
- The activation condition is overly broad because it triggers on very common content such as version numbers, dates, API references, and model names. In practice this can cause unnecessary invocation of the skill in many unrelated contexts, increasing the chance of needless external checks, tool usage, and user friction; in an agentic system, broad activation can also expand the attack surface by causing the skill to run on adversarially crafted text.
