Vague Triggers
Medium
- Confidence
- 86% confidence
- Finding
- The trigger text says to use this skill for ANY LiveSession request and instead of calling the API directly, which is broader than necessary and can cause the agent to invoke the skill for loosely related tasks without sufficient user intent validation. In this skill, the exposed action is read-only, so the main risk is unintended data access or over-collection rather than direct state-changing harm.
