Vague Triggers
Medium
- Confidence
- 67% confidence
- Finding
- The description says the skill should be used when installing new skills from ClawHub, but it does not clearly constrain who triggers it, under what exact conditions, or whether it should ever act automatically. Broad activation language around install flows can cause an agent to invoke shell-based install logic in situations that were not explicitly approved by the user.
