Vague Triggers
Medium
- Confidence
- 91% confidence
- Finding
- The skill declares it should be used for ANY Google Photos request and whenever a task involves Google Photos, which is an overly broad routing instruction. This can cause the agent to invoke the skill outside a narrowly scoped, least-privilege context and increases the chance of unnecessary access to read/write/delete operations, especially since the skill exposes destructive actions.
