Vague Triggers
Medium
- Confidence
- 91% confidence
- Finding
- The manifest description includes broad triggers such as "release," "audit code," "check docs," and "publish," which can match many ordinary developer requests and cause the skill to activate outside a narrowly intended context. Because this skill can proceed into fix and release flows that modify files, create tags, and publish artifacts, overly permissive triggering increases the chance of unintended invocation and unsafe repository actions.
