Vague Triggers
Medium
- Confidence
- 92% confidence
- Finding
- The skill’s invocation guidance is very broad, covering generic requests like 'build me an app/site/webapp,' which can cause the agent to trigger this powerful scaffold-and-deploy workflow for ambiguous user intents. Because the skill has access to exec, file-writing, browser, and deployment-related tooling, overbroad activation increases the chance of unintended repository creation, code generation, and deployment actions in contexts where a narrower skill or additional confirmation should have been used.
