Vague Triggers
Medium
- Confidence
- 85% confidence
- Finding
- The trigger text is overly broad: 'Use this skill for ANY VectorShift request' and 'Whenever a task involves VectorShift, use this skill instead of calling the API directly' can cause the agent to invoke the skill for any mention of VectorShift, even when the user only wants discussion, comparison, or unrelated context. This increases the chance of unintended tool execution and unnecessary access to connected account data.
