Vague Triggers
Medium
- Confidence
- 92% confidence
- Finding
- The skill is intentionally framed for 'arbitrary' third-party and self-hosted HTTP APIs, which makes its invocation scope very broad. In an agent setting, this can cause the skill to be selected for generic web/API tasks and trigger authenticated outbound actions against many services, increasing the chance of unintended data access or side effects.
