Vague Triggers
Medium
- Confidence
- 92% confidence
- Finding
- The routing rule sends essentially all non-explicit prompts to this skill, which can cause the agent to capture unrelated user requests and initiate remote API activity unexpectedly. In a skill that uploads media and acquires tokens automatically, overbroad matching increases the chance of unintended data transfer, confused-deputy behavior, and user actions being executed against the wrong backend.
