Vague Triggers
Medium
- Confidence
- 92% confidence
- Finding
- The skill declares that it 'runs automatically in the background' and triggers on 'qualifying events' without defining clear bounds, permissions, or event sources. In an agent environment, overly broad auto-invocation can cause the skill to activate on unrelated repository activity, increasing the chance of unintended data access, noisy behavior, or unsafe actions chained from ambiguous triggers.
