Vague Triggers
Medium
- Confidence
- 92% confidence
- Finding
- The invocation text is overly broad: 'Use this skill for ANY Leonardo.Ai request' and 'Whenever a task involves Leonardo.Ai, use this skill instead of calling the API directly' can cause an agent to route any Leonardo-related mention into a tool-capable skill, even when the user did not ask to act. In a skill that includes write actions and shell execution via Bash, this increases the chance of unintended connector calls, schema probing, or account-state changes from ambiguous prompts.
