Vague Triggers
Medium
- Confidence
- 93% confidence
- Finding
- The plugin declares activation on broad capability classes (provider, channel, tool, hook, context-engine) rather than narrowly scoped events, which can cause it to load in many unrelated workflows. In a plugin that exposes a large API surface with tools, hooks, providers, and channel features, this increases the attack surface and the chance of unintended invocation, privilege exposure, or unsafe interaction paths if any downstream component is weak.
