Vague Triggers
Medium
- Confidence
- 89% confidence
- Finding
- The skill allows implicit invocation, but the manifest does not define clear trigger constraints, exclusions, or scope boundaries. That can cause the agent to auto-select this skill in loosely related contexts, increasing the chance of unintended code generation or advice being applied where shader-specific behavior was not requested, which expands the attack surface for prompt-routing mistakes or misuse.
