Vague Triggers
Medium
- Confidence
- 90% confidence
- Finding
- The trigger sentences and keywords are overly broad, including generic terms like "security," "first," "before," and "github," which can cause the skill to activate in contexts unrelated to its intended purpose. In an agent environment, ambiguous activation increases the chance of misrouting user requests, unintended workflow execution, or an attacker deliberately invoking the skill when a narrower, safer tool should have handled the task.
