Vague Triggers
Medium
- Confidence
- 96% confidence
- Finding
- The trigger list is broad enough that the skill may activate on generic terms like 'security' or 'testing', causing the agent to invoke a capability that generates malicious WAF test traffic in contexts the user may not intend. In a security-testing skill, accidental activation is more dangerous because the workflow includes offensive scanning guidance and payload generation against targets.
