Vague Triggers
Medium
- Confidence
- 82% confidence
- Finding
- The activation guidance uses broad natural-language triggers such as '帮我验一下这张增值税发票' and '这张票能不能报销查验', which could cause the skill to activate on loosely related requests. Because the skill sends sensitive invoice details to a third-party verification service, overbroad activation increases the chance of unintended data disclosure or unexpected external calls.
