Vague Triggers
Medium
- Confidence
- 88% confidence
- Finding
- The catch-all routing rule sends essentially any unmatched request into the SSE/edit pipeline, which increases the chance of unintended activation and remote actions against the backend. In a skill that can upload content, query state, and initiate rendering sessions, overly broad triggering can cause accidental data submission or actions the user did not clearly authorize.
