Vague Triggers
Medium
- Confidence
- 88% confidence
- Finding
- The skill description and metadata market the capability in very broad terms ('lets them pay', 'authorized actor at any UCP-compliant merchant') without clearly constraining when an agent should invoke it. In practice, this can cause over-activation in loosely related commerce contexts, leading an agent to disclose identity credentials or initiate payment flows more often than intended.
