Vague Triggers
Medium
- Confidence
- 84% confidence
- Finding
- The trigger format is too loosely specified: it accepts both a local image path or a URL plus a token, without defining trust boundaries, validation rules, or exclusions. In an agent setting, this ambiguity can lead to unsafe behavior such as fetching attacker-controlled remote content, uploading unintended local files, or mishandling sensitive bearer tokens supplied in natural language.
