Vague Triggers
Medium
- Confidence
- 84% confidence
- Finding
- The activation condition is overly broad: it instructs the agent to use this skill for ANY Google Cloud STS request, without limiting by user intent, sensitivity, or task type. In context, this is more dangerous because the only exposed action mints a Google Cloud access token, so an overbroad trigger can cause unnecessary or premature credential retrieval for loosely related requests.
