Vague Triggers
Medium
- Confidence
- 94% confidence
- Finding
- The trigger text instructs the agent to use this skill for ANY BambooHR request and whenever a task involves BambooHR, which is broader than a narrowly scoped read-only skill selector should be. This can cause unintended invocation on vague mentions of BambooHR and route sensitive HR data queries through the skill without sufficient task disambiguation, increasing the chance of privacy-impacting overreach or misuse.
