Vague Triggers
Medium
- Confidence
- 94% confidence
- Finding
- The release text claims the skill 'automatically takes effect after installation' and records 'any new task' without defining scope, triggers, exclusions, or requiring explicit user confirmation. This kind of broad autonomous behavior can cause unintended data capture and persistence, especially if ordinary conversation items or sensitive requests are interpreted as tasks and written to workspace files.
