Vague Triggers
Medium
- Confidence
- 91% confidence
- Finding
- The skill’s activation guidance is vague enough that an agent could invoke it for loosely related 'support' or 'communication' tasks without the user clearly intending to contact an external helpdesk system. In a skill that likely performs ticketing actions and may transmit data using an API key, overly broad use conditions increase the risk of unintended external actions or disclosure of user information.
