Vague Triggers
Medium
- Confidence
- 88% confidence
- Finding
- The description says to use this skill for ANY Google Calendar request and instead of calling the API directly, which is an overly broad routing instruction. This can cause the agent to invoke a high-privilege skill in cases where narrower, safer handling or additional policy checks would be more appropriate, increasing the chance of unintended data access or state changes.
