Vague Triggers
Medium
- Confidence
- 89% confidence
- Finding
- The routing table sends all unmatched user input to the SSE generation action, which means arbitrary prompts and accidental inputs are forwarded to a remote backend by default. In a skill that accepts free-form text and files, this increases the chance of unintended data disclosure, surprising network actions, and abuse of paid/limited backend operations without explicit user intent.
