Vague Triggers
Medium
- Confidence
- 93% confidence
- Finding
- The skill description says it may auto-trigger 'after task completion' and lists broad trigger words like 质检/验收/交叉检查, which can cause the pipeline to activate in situations the user did not explicitly authorize. Because the workflow includes opening files, checking paths, and escalating to multiple agents, ambiguous activation can expand access to user artifacts and create unintended data exposure or unnecessary processing.
