Vague Triggers
Medium
- Confidence
- 88% confidence
- Finding
- The skill advertises itself for essentially any production development task, which makes it easy for an agent to invoke it in situations where safer, narrower, task-specific workflows would be more appropriate. Because the workflow includes broad repository-changing actions like `git add -A`, PR creation, issue creation, and deployment checks, overbroad activation increases the chance of unintended code changes, disclosure through external tooling, or autonomous actions taken without sufficient user confirmation.
