Vague Triggers
Medium
- Confidence
- 93% confidence
- Finding
- The manifest description contains very broad trigger phrases such as generic security, compliance, discovery, and 'is this agent safe?' prompts, which can cause the skill to be invoked in situations where the user did not clearly intend to call an external verification service. In this skill's context, unintended invocation is more dangerous because many flows lead to authenticated API requests and may expose user queries, agent identifiers, or organization context to a remote service.
