Vague Triggers
Medium
- Confidence
- 94% confidence
- Finding
- The skill declares it should trigger on both several named phrases and also on "any explicit ask to edit with this model," which is an overly broad activation rule. Broad triggers can cause the skill to activate in contexts the user did not clearly intend, leading to unintended execution of a third-party CLI, transmission of user-provided image URLs and prompts to a remote service, and possible misuse of local credentials such as RUNCOMFY_TOKEN.
