Vague Triggers
Medium
- Confidence
- 93% confidence
- Finding
- The skill states users can 'directly send files' and that the system will automatically process them by format, but it does not define trigger boundaries, file-type exclusions beyond examples, or safety checks before parsing. Broad automatic invocation increases the chance of unintended processing of sensitive, unsupported, or risky files and can lead to privacy issues or unsafe downstream handling.
