Vague Triggers
Medium
- Confidence
- 85% confidence
- Finding
- The skill description says to use this skill for ANY TaxJar request and instead of calling the API directly, which is an overly broad routing rule. This can cause the agent to invoke a high-privilege finance/data skill for loosely related tasks without sufficient narrowing, increasing the chance of unintended reads, writes, or destructive operations in a sensitive service.
