Vague Triggers
Medium
- Confidence
- 92% confidence
- Finding
- The invocation rule is overly broad because it triggers on many generic privacy-related terms such as "personal data," "data privacy," and "GDPR compliance," which can appear in contexts where the user is not actually asking to create or edit a privacy policy page. This can cause unintended skill activation, leading the agent to produce legal-page guidance when a narrower privacy, security, or compliance response was intended.
