Vague Triggers
Medium
- Confidence
- 91% confidence
- Finding
- The skill enables implicit invocation without any visible activation constraints, which can cause the agent to call this external image-generation capability when the user did not explicitly request it. Because this skill sends user prompts to a third-party service, overbroad auto-invocation can lead to unintended data sharing, unexpected actions, or prompt-triggered abuse through ambiguous requests.
