Vague Triggers
Medium
- Confidence
- 90% confidence
- Finding
- The manifest description includes very broad trigger phrases such as general image/video/text-to-speech generation requests, which can cause the skill to activate in many contexts without clear user intent to use HuggingFace services. Because this skill sends prompts and possibly files to third-party Spaces or inference providers, overbroad activation increases the chance of unintended external data disclosure or execution of external-service workflows.
