Vague Triggers
Medium
- Confidence
- 84% confidence
- Finding
- The trigger keyword "什么值得买" is broad and closely matches common user requests about the well-known shopping site, which can cause the skill to activate when a user did not specifically intend to invoke it. This creates an unintended-invocation risk that may route user queries into scraping behavior unexpectedly, though it does not by itself enable code execution or direct compromise.
