Vague Triggers
Medium
- Confidence
- 84% confidence
- Finding
- The invocation guidance is broad enough to activate the shopping skill for many generic product-related conversations, which can cause unnecessary routing to a third-party MCP server and disclosure of user queries that may not need external handling. While the skill is not overtly malicious and only exposes shopping-oriented functionality, the lack of tighter scoping increases privacy and overreach risk.
