Vague Triggers
Medium
- Confidence
- 87% confidence
- Finding
- The trigger phrases are broad natural-language requests like "why does this code exist" and "what's the history of this," which can cause the skill to activate in ordinary conversation rather than only on explicit invocation. That creates a real security and safety issue because it may unexpectedly run repository-inspection commands on sensitive local codebases when the user did not intend to invoke this tool.
