Vague Triggers
Medium
- Confidence
- 94% confidence
- Finding
- The skill uses broad trigger phrases like 'see what Hermes thinks about this' that could match normal conversational requests and cause unintended delegation to an external local CLI agent. Because activation results in command execution and prompt forwarding to another agent, accidental invocation materially increases the chance of unreviewed data disclosure or tool use outside the user's expectations.
