Vague Triggers
Medium
- Confidence
- 86% confidence
- Finding
- The skill activates on a very general condition ('when the user invokes this skill') without narrower trigger constraints or safety gating, which increases the chance it will be used in contexts where it inspects the system, reads sensitive files, or suggests risky hardening actions without clear scoping. In a security-focused skill, broad invocation is more dangerous because the described workflow includes checking system state and scanning locations like .env, .bashrc, and environment variables, which can expose sensitive data if invoked too freely.
