Vague Triggers
Medium
- Confidence
- 83% confidence
- Finding
- The description instructs use of the skill for ANY Clockify request and instead of calling the API directly, which is broad enough to cause over-invocation whenever Clockify is mentioned. In an agent setting, this can lead to unintended tool execution paths, including state-changing operations, especially because the same skill exposes both read and write/delete actions.
