Vague Triggers
Medium
- Confidence
- 89% confidence
- Finding
- The trigger list includes very broad standalone terms like "NIST", "OWASP", and "EU AI Act", which can cause the skill to be selected for generic framework-related queries outside its intended compliance-evaluation scope. This creates a prompt-routing risk where the skill may activate in contexts involving advisory, interpretation, or unrelated security tasks, increasing the chance of inappropriate tool use or confusing capability escalation.
