Vague Triggers
Medium
- Confidence
- 89% confidence
- Finding
- The skill advertises very broad trigger phrases such as 'an alert fires,' 'something is down,' and 'investigating an incident,' which can cause the agent to invoke this skill in many loosely related contexts. Over-broad invocation increases the chance the skill activates on ambiguous operational language, pulling in alert text, links, or webhook content that may be attacker-controlled and causing unintended actions like triage workflows, GitHub correlation, or incident ticket creation.
