Vague Triggers
Medium
- Confidence
- 92% confidence
- Finding
- The manifest description says to use this skill for "ANY Personal AI request" and "instead of calling the API directly," which is an overly broad trigger that can cause the agent to invoke the skill in situations where more constrained or safer handling would be appropriate. Broad invocation criteria increase the attack surface for unintended writes, schema-driven command construction, and execution of setup steps involving external tooling.
