Vague Triggers
Medium
- Confidence
- 89% confidence
- Finding
- The README states the AI will automatically invoke the skill 'when needed' and also provides a very broad trigger phrase ('检查系统状态'). This can cause unintended activation in loosely related conversations, leading to unnecessary system inspection and disclosure of environment details such as versions, configuration status, cron state, and memory artifacts. In a diagnostic skill, broad auto-triggering increases risk because the skill touches sensitive operational metadata even if it does not itself appear overtly malicious.
