Vague Triggers
Medium
- Confidence
- 92% confidence
- Finding
- The trigger phrases are broad natural-language patterns such as "STT ...", "ASR ...", and "Transcribe ...", which can match ordinary user requests rather than an explicit invocation. This increases the chance the skill runs unexpectedly on user-provided audio paths or transcription requests, creating unintended execution and expanding the attack surface for any installation or runtime behavior in the referenced scripts.
