Vague Triggers
Medium
- Confidence
- 88% confidence
- Finding
- The skill description is overly broad and says to use the skill whenever the user wants to interact with GitHub data, without narrowing scope to safe, intended operations. In an agentic environment, this can cause over-selection of the skill for ambiguous GitHub requests and increase the chance of unintended repository reads or write operations being proposed or executed.
