Vague Triggers
Medium
- Confidence
- 91% confidence
- Finding
- The trigger list includes broad phrases such as 'official account', 'bank card', and 'MCP server' that can plausibly appear in unrelated conversations, causing the skill to activate outside a clear Zalo-specific context. In a skill that can send messages, forward webhook data, and interact with account features, accidental invocation increases the risk of unintended actions or disclosure.
