Vague Triggers
Medium
- Confidence
- 86% confidence
- Finding
- The instruction to use this skill for "ANY Tavily request" is overly broad and can cause the agent to invoke the skill whenever Tavily is merely mentioned, even when the user did not ask to use this connector or when a safer/local alternative would suffice. This increases the chance of unintended external calls, unnecessary data disclosure to a third-party service, and workflow hijacking through aggressive routing.
