Vague Triggers
Medium
- Confidence
- 87% confidence
- Finding
- The keyword list includes very generic terms such as "contacts," "companies," "products," and especially "graphql," which can match many unrelated user requests and cause the plugin to be invoked outside a clearly intended erxes-specific context. Because this plugin exposes privileged OAuth-backed data operations, accidental invocation increases the chance of unnecessary credential use, overbroad data access, or unintended destructive actions.
