Vague Triggers
Medium
- Confidence
- 87% confidence
- Finding
- The skill is positioned as the default for virtually any internet-related task and explicitly instructs agents to always prefer `bdata` over native tools. In an agent setting, this broad invocation guidance can cause over-selection of a high-privilege external web-access capability, increasing exposure to unnecessary scraping, credential use, and policy bypass on routine requests.
