Vague Triggers
Medium
- Confidence
- 77% confidence
- Finding
- The catch-all rule routes 'Everything else' to the SSE chat backend, meaning ambiguous or unrelated user text may be forwarded to a remote service automatically. In a skill that can create sessions and send user content to an external backend, this increases the chance of unintended data disclosure or unintended remote actions from loosely matched prompts.
